NVIDIA
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any NVIDIA product.
RSS Feeds for NVIDIA security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in NVIDIA products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by NVIDIA Sorted by Most Security Vulnerabilities since 2018
Recent NVIDIA Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 5869 | Security Bulletin - NVIDIA - Transformers4Rec - July 2026 | July 21, 2026 |
| 5840 | Security Bulletin: NVIDIA TensorRT-LLM - July 2026 | July 14, 2026 |
| 5853 | Security Bulletin: NVIDIA Triton Inference Server - July 2026 | July 14, 2026 |
| 5855 | Security Bulletin: NVIDIA TensorRT - July 2026 | July 14, 2026 |
| 5841 | Security Bulletin: NVIDIA Megatron Bridge - June 2026 | June 30, 2026 |
| 5849 | Security Bulletin: NVIDIA AIStore Framework - June 2026 | June 30, 2026 |
| 5699 | Security Bulletin: NVIDIA Networking Bluefield and ConnectX - June 2026 | June 30, 2026 |
| 5848 | Security Bulletin: NVIDIA Triton Inference Server - June 2026 | June 30, 2026 |
| 5850 | Security Bulletin: NVIDIA Container Toolkit - June 2026 | June 30, 2026 |
| 5839 | Security Bulletin: NVIDIA NeMo - June 2026 | June 16, 2026 |
By the Year
In 2026 there have been 140 vulnerabilities in NVIDIA with an average score of 7.4 out of ten. Last year, in 2025 NVIDIA had 174 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in NVIDIA in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.66.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 140 | 7.41 |
| 2025 | 174 | 6.74 |
| 2024 | 34 | 6.81 |
| 2023 | 28 | 6.22 |
| 2022 | 43 | 6.70 |
| 2021 | 75 | 6.54 |
| 2020 | 35 | 6.78 |
| 2019 | 16 | 6.90 |
| 2018 | 7 | 5.50 |
It may take a day or so for new NVIDIA vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent NVIDIA Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-24232 | Jul 21, 2026 |
Deserialization RCE in NVIDIA Transformers4RecNVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-24272 | Jul 14, 2026 |
TensorRT Heap Buffer Overflow VulnerabilityNVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24268 | Jul 14, 2026 |
NVIDIA TensorRT Heap Buffer Overflow (CVE-2026-24268) Allows Code ExecutionNVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24238 | Jul 14, 2026 |
NVIDIA TensorRT Improper Array Index Validation Allows Code ExecutionNVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24227 | Jul 14, 2026 |
Untrusted Deserialization in NVIDIA TensorRT Code Exec (CVE-2026-24227)NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24271 | Jul 14, 2026 |
NVIDIA TensorRT-LLM GPU Allocation Exhaustion via OpenAI APINVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47475 | Jul 14, 2026 |
TensorRTLLM OpenAI API Assertion Trigger Leads to DoSNVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47470 | Jul 14, 2026 |
NVIDIA TensorRT-LLM gRPC Chat API CWE-20 Local AttackNVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-24226 | Jul 14, 2026 |
Improper Control of Code Generation in NVIDIA TensorRTLLM Leads to Code ExecutionNVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-24259 | Jul 14, 2026 |
Missing Auth in NVIDIA TensorRT-LLM Critical Function (CVE-2026-24259)NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-24220 | Jul 14, 2026 |
Unsafe ZeroMQ Deserialization in NVIDIA TensorRT-LLM VisualGenNVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24234 | Jul 14, 2026 |
NVIDIA TensorRT-LLM SSRF via Media Fetching (CVE-2026-24234)NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure. |
|
| CVE-2026-24229 | Jul 14, 2026 |
NVIDIA TensorRT-LLM Disaggregated Orchestrator Allows Full Cluster State AccessNVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. |
|
| CVE-2026-47473 | Jul 14, 2026 |
TensorRT-LLM Write-What-Where Vulnerability Enables Data TamperingNVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. |
|
| CVE-2026-47471 | Jul 14, 2026 |
NVIDIA TensorRT-LLM Heap-Based Buffer Overflow via Tensor DeserializationNVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service. |
|
| CVE-2026-47472 | Jul 14, 2026 |
NVIDIA TensorRT-LLM IPC deserialization flaw allows local code executionNVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service. |
|
| CVE-2026-24233 | Jul 14, 2026 |
TensorRT-LLM Restricted Unpickler Deserialization Exploit (Code Exec)NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-47482 | Jul 14, 2026 |
Memory Leak in NVIDIA Triton Inference Server Causes DoSNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47481 | Jul 14, 2026 |
NVIDIA Triton Inference Server Auth Bypass via Alternate ChannelNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47480 | Jul 14, 2026 |
DDoS via Uncaught Exception in NVIDIA Triton Inference ServerNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47479 | Jul 14, 2026 |
DoS via Resource Exhaustion in NVIDIA Triton Inference Server (Linux)NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47478 | Jul 14, 2026 |
NVIDIA Triton Server DoS via expired FD abuseNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47477 | Jul 14, 2026 |
NVIDIA Triton Inference Server Stack Buffer Overflow CVE-2026-47477NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47476 | Jul 14, 2026 |
NVIDIA Triton Inference Server Uncontrolled Resource DoSNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-24270 | Jul 01, 2026 |
NVIDIA AIStore Auth Bypass CVE-2026-24270NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-24266 | Jul 01, 2026 |
UAF in NVIDIA Triton Inference Server (Linux)NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-24264 | Jul 01, 2026 |
NVIDIA Triton Inference Server DoS via High Compression ExploitNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-24251 | Jul 01, 2026 |
Code Execution via Improper Resource Control in NVIDIA Megatron Bridge on LinuxNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24250 | Jul 01, 2026 |
NVIDIA Megatron Bridge for Linux: Improper Input Validation Leading to Code ExecutionNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24249 | Jul 01, 2026 |
NVIDIA Megatron Bridge Deserialization Flaw CVE-2026-24249NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24248 | Jul 01, 2026 |
Improper Code Generation in NVIDIA Megatron Bridge for LinuxNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24247 | Jul 01, 2026 |
Deserialization Flaw in NVIDIA Megatron Bridge (Linux)NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24246 | Jul 01, 2026 |
NVIDIA Megatron Bridge for Linux: Improper Control of Dynamically Managed CodeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24245 | Jul 01, 2026 |
Untrusted Deserialization in NVIDIA Megatron Bridge for Linux Enables RCENVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24244 | Jul 01, 2026 |
NVIDIA Megatron Bridge Linux Untrusted Deserialization RCE CVE-2026-24244NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24243 | Jul 01, 2026 |
Deserialization in NVIDIA Megatron Bridge for Linux may lead to code executionNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24242 | Jul 01, 2026 |
CVE-2026-24242 NVIDIA Megatron Bridge SSRF Info DisclosureNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-24240 | Jul 01, 2026 |
Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux Enables RCENVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2025-23351 | Jul 01, 2026 |
OOB Write via VF Request in NVIDIA ConnectX/BlueField Command InterfaceNVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. |
|
| CVE-2025-23350 | Jul 01, 2026 |
NVIDIA ConnectX/BlueField VF OOB Write Arbitrary ExecutionNVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. |
|
| CVE-2026-24260 | Jul 01, 2026 |
NVIDIA Container Toolkit Linux TC-TOU Race Enables Escalation & Data TamperingNVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering. |
|
| CVE-2026-24228 | Jun 16, 2026 |
NVIDIA NeMo Framework Deserialization Flaw Enables Remote Code ExecNVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24155 | Jun 16, 2026 |
NVIDIA NeMo Framework Code Injection VulnerabilityNVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-24180 | Jun 09, 2026 |
Heap overflow in NVIDIA DALI may allow code executionNVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-24181 | Jun 09, 2026 |
CVE-2026-24181: NVIDIA DALI Improper IDX Validation Exploitable for RCENVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-24237 | Jun 02, 2026 |
NVTabular Improper Deserialization RCE & Info DisclosureNVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-24221 | Jun 02, 2026 |
NVTabular Untrusted Deserialization Remote Code Execution (CVE-2026-24221)NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering and information disclosure. |
|
| CVE-2025-33221 | May 26, 2026 |
NVIDIA Display Driver Kernel Permission Flaw (CVE-2025-33221)NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service. |
|
| CVE-2026-24201 | May 26, 2026 |
NVIDIA vGPU Software OOB Access in Virtual GPU Manager (CVE-2026-24201)NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering, denial of service, or information disclosure. |
|
| CVE-2026-24200 | May 26, 2026 |
Use-After-Free in NVIDIA vGPU Virtual GPU Manager leads to DoS & Priv EscalationNVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution. |
|