Executive brief
NVIDIA Dynamo for Linux is a machine learning platform that processes multimodal requests (combining text, images, and other data types). An attacker can exploit a vulnerability by providing a specially crafted URL, causing the server to make unintended requests to internal systems, potentially exposing sensitive information like credentials or internal data.
Technical details
This vulnerability is a server-side request forgery (SSRF) flaw in NVIDIA Dynamo for Linux that can be triggered via a malicious URL supplied in a multimodal request. The vulnerable component does not properly validate or sanitize URLs before processing them, allowing an attacker to redirect server-side requests to arbitrary internal or external resources. The attack requires network access to the Dynamo service and the ability to send crafted multimodal requests. Successful exploitation leads to information disclosure by accessing internal resources or metadata that should not be exposed. Patches are expected from NVIDIA; users should check the NVIDIA security advisory for version guidance and mitigation steps.
Affected products
- NVIDIA Dynamo <UNKNOWN>
Timeline
- 2026-08-04: disclosed: CVE-2026-47615 published