NVIDIA NVIDIA

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any NVIDIA product.

RSS Feeds for NVIDIA security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in NVIDIA products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by NVIDIA Sorted by Most Security Vulnerabilities since 2018

NVIDIA Gpu Display Driver78 vulnerabilities

NVIDIA Triton Inference Server57 vulnerabilities

NVIDIA Virtual Gpu Manager46 vulnerabilities

NVIDIA Cuda Toolkit44 vulnerabilities

NVIDIA Nemo32 vulnerabilities

NVIDIA Geforce26 vulnerabilities

NVIDIA Tesla25 vulnerabilities

NVIDIA Jetson22 vulnerabilities

NVIDIA Geforce Experience18 vulnerabilities

NVIDIA Megatron Lm11 vulnerabilities

NVIDIA Gpu Driver7 vulnerabilities

NVIDIA Cumulus Linux3 vulnerabilities

NVIDIA Mlnx Os3 vulnerabilities

NVIDIA Onyx3 vulnerabilities

NVIDIA Aistore3 vulnerabilities

NVIDIA Bluefield1 vulnerability

Nvidia Gpu Operator1 vulnerability

NVIDIA Quadro1 vulnerability

NVIDIA Runai1 vulnerability

NVIDIA Skyway1 vulnerability

NVIDIA Studio1 vulnerability

NVIDIA Titan V Firmware1 vulnerability

NVIDIA Connectx1 vulnerability

NVIDIA Cv Cuda1 vulnerability

NVIDIA Igx1 vulnerability

NVIDIA Isaac Lab1 vulnerability

NVIDIA Jetson Linux1 vulnerability

Nvidia Container Toolkit1 vulnerability

NVIDIA Mellanox Os1 vulnerability

NVIDIA Metrox 21 vulnerability

NVIDIA Metrox 3 Xc1 vulnerability

NVIDIA Nsight Graphics1 vulnerability

NVIDIA Nvapp1 vulnerability

NVIDIA Nvdebug Tool1 vulnerability

Nvidia App1 vulnerability

Recent NVIDIA Security Advisories

Advisory Title Published
5869 Security Bulletin - NVIDIA - Transformers4Rec - July 2026 July 21, 2026
5840 Security Bulletin: NVIDIA TensorRT-LLM - July 2026 July 14, 2026
5853 Security Bulletin: NVIDIA Triton Inference Server - July 2026 July 14, 2026
5855 Security Bulletin: NVIDIA TensorRT - July 2026 July 14, 2026
5841 Security Bulletin: NVIDIA Megatron Bridge - June 2026 June 30, 2026
5849 Security Bulletin: NVIDIA AIStore Framework - June 2026 June 30, 2026
5699 Security Bulletin: NVIDIA Networking Bluefield and ConnectX - June 2026 June 30, 2026
5848 Security Bulletin: NVIDIA Triton Inference Server - June 2026 June 30, 2026
5850 Security Bulletin: NVIDIA Container Toolkit - June 2026 June 30, 2026
5839 Security Bulletin: NVIDIA NeMo - June 2026 June 16, 2026

By the Year

In 2026 there have been 140 vulnerabilities in NVIDIA with an average score of 7.4 out of ten. Last year, in 2025 NVIDIA had 174 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in NVIDIA in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.66.




Year Vulnerabilities Average Score
2026 140 7.41
2025 174 6.74
2024 34 6.81
2023 28 6.22
2022 43 6.70
2021 75 6.54
2020 35 6.78
2019 16 6.90
2018 7 5.50

It may take a day or so for new NVIDIA vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent NVIDIA Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-24232 Jul 21, 2026
Deserialization RCE in NVIDIA Transformers4Rec NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-24272 Jul 14, 2026
TensorRT Heap Buffer Overflow Vulnerability NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24268 Jul 14, 2026
NVIDIA TensorRT Heap Buffer Overflow (CVE-2026-24268) Allows Code Execution NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24238 Jul 14, 2026
NVIDIA TensorRT Improper Array Index Validation Allows Code Execution NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24227 Jul 14, 2026
Untrusted Deserialization in NVIDIA TensorRT Code Exec (CVE-2026-24227) NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24271 Jul 14, 2026
NVIDIA TensorRT-LLM GPU Allocation Exhaustion via OpenAI API NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-47475 Jul 14, 2026
TensorRTLLM OpenAI API Assertion Trigger Leads to DoS NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-47470 Jul 14, 2026
NVIDIA TensorRT-LLM gRPC Chat API CWE-20 Local Attack NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-24226 Jul 14, 2026
Improper Control of Code Generation in NVIDIA TensorRTLLM Leads to Code Execution NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-24259 Jul 14, 2026
Missing Auth in NVIDIA TensorRT-LLM Critical Function (CVE-2026-24259) NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-24220 Jul 14, 2026
Unsafe ZeroMQ Deserialization in NVIDIA TensorRT-LLM VisualGen NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.
CVE-2026-24234 Jul 14, 2026
NVIDIA TensorRT-LLM SSRF via Media Fetching (CVE-2026-24234) NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
CVE-2026-24229 Jul 14, 2026
NVIDIA TensorRT-LLM Disaggregated Orchestrator Allows Full Cluster State Access NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
CVE-2026-47473 Jul 14, 2026
TensorRT-LLM Write-What-Where Vulnerability Enables Data Tampering NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CVE-2026-47471 Jul 14, 2026
NVIDIA TensorRT-LLM Heap-Based Buffer Overflow via Tensor Deserialization NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.
CVE-2026-47472 Jul 14, 2026
NVIDIA TensorRT-LLM IPC deserialization flaw allows local code execution NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service.
CVE-2026-24233 Jul 14, 2026
TensorRT-LLM Restricted Unpickler Deserialization Exploit (Code Exec) NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-47482 Jul 14, 2026
Memory Leak in NVIDIA Triton Inference Server Causes DoS NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47481 Jul 14, 2026
NVIDIA Triton Inference Server Auth Bypass via Alternate Channel NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Triton Inference Server
CVE-2026-47480 Jul 14, 2026
DDoS via Uncaught Exception in NVIDIA Triton Inference Server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47479 Jul 14, 2026
DoS via Resource Exhaustion in NVIDIA Triton Inference Server (Linux) NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47478 Jul 14, 2026
NVIDIA Triton Server DoS via expired FD abuse NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47477 Jul 14, 2026
NVIDIA Triton Inference Server Stack Buffer Overflow CVE-2026-47477 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-47476 Jul 14, 2026
NVIDIA Triton Inference Server Uncontrolled Resource DoS NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-24270 Jul 01, 2026
NVIDIA AIStore Auth Bypass CVE-2026-24270 NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
Aistore
CVE-2026-24266 Jul 01, 2026
UAF in NVIDIA Triton Inference Server (Linux) NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-24264 Jul 01, 2026
NVIDIA Triton Inference Server DoS via High Compression Exploit NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service.
Triton Inference Server
CVE-2026-24251 Jul 01, 2026
Code Execution via Improper Resource Control in NVIDIA Megatron Bridge on Linux NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24250 Jul 01, 2026
NVIDIA Megatron Bridge for Linux: Improper Input Validation Leading to Code Execution NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24249 Jul 01, 2026
NVIDIA Megatron Bridge Deserialization Flaw CVE-2026-24249 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24248 Jul 01, 2026
Improper Code Generation in NVIDIA Megatron Bridge for Linux NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24247 Jul 01, 2026
Deserialization Flaw in NVIDIA Megatron Bridge (Linux) NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24246 Jul 01, 2026
NVIDIA Megatron Bridge for Linux: Improper Control of Dynamically Managed Code NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24245 Jul 01, 2026
Untrusted Deserialization in NVIDIA Megatron Bridge for Linux Enables RCE NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24244 Jul 01, 2026
NVIDIA Megatron Bridge Linux Untrusted Deserialization RCE CVE-2026-24244 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24243 Jul 01, 2026
Deserialization in NVIDIA Megatron Bridge for Linux may lead to code execution NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-24242 Jul 01, 2026
CVE-2026-24242 NVIDIA Megatron Bridge SSRF Info Disclosure NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CVE-2026-24240 Jul 01, 2026
Deserialization Vulnerability in NVIDIA Megatron Bridge for Linux Enables RCE NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2025-23351 Jul 01, 2026
OOB Write via VF Request in NVIDIA ConnectX/BlueField Command Interface NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
CVE-2025-23350 Jul 01, 2026
NVIDIA ConnectX/BlueField VF OOB Write Arbitrary Execution NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
CVE-2026-24260 Jul 01, 2026
NVIDIA Container Toolkit Linux TC-TOU Race Enables Escalation & Data Tampering NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.
CVE-2026-24228 Jun 16, 2026
NVIDIA NeMo Framework Deserialization Flaw Enables Remote Code Exec NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure.
Nemo
CVE-2026-24155 Jun 16, 2026
NVIDIA NeMo Framework Code Injection Vulnerability NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Nemo
CVE-2026-24180 Jun 09, 2026
Heap overflow in NVIDIA DALI may allow code execution NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CVE-2026-24181 Jun 09, 2026
CVE-2026-24181: NVIDIA DALI Improper IDX Validation Exploitable for RCE NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CVE-2026-24237 Jun 02, 2026
NVTabular Improper Deserialization RCE & Info Disclosure NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-24221 Jun 02, 2026
NVTabular Untrusted Deserialization Remote Code Execution (CVE-2026-24221) NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering and information disclosure.
CVE-2025-33221 May 26, 2026
NVIDIA Display Driver Kernel Permission Flaw (CVE-2025-33221) NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.
Geforce
Tesla
CVE-2026-24201 May 26, 2026
NVIDIA vGPU Software OOB Access in Virtual GPU Manager (CVE-2026-24201) NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering, denial of service, or information disclosure.
Virtual Gpu Manager
CVE-2026-24200 May 26, 2026
Use-After-Free in NVIDIA vGPU Virtual GPU Manager leads to DoS & Priv Escalation NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
Virtual Gpu Manager
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.