NVIDIA NemoClaw: Inference Service Bypass (auth) Info Leak & DoS
CVE-2026-65105 Published on August 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
HIGH

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-65105

Want to know whenever a new CVE is published for NVIDIA Nemo? stack.watch will email you.

 

Affected Versions

NVIDIA NemoClaw Version 0 to 0.0.25 is affected by CVE-2026-65105