Executive brief
NVIDIA Dynamo for Linux is a data processing platform used for machine learning workflows. A vulnerability in its media handling component allows attackers to make unauthorized server-side requests, potentially exposing sensitive information from internal systems or services not directly accessible over the network.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the multimodal media fetcher component of NVIDIA Dynamo for Linux. An attacker can exploit this to make the server issue requests to arbitrary internal or external services, bypassing network access controls. The attack is network-reachable and does not require prior authentication based on the CVSS score. Successful exploitation may lead to information disclosure from internal systems. Patches are expected from NVIDIA following the public disclosure.
Affected products
- NVIDIA Dynamo for Linux <UNKNOWN>
Timeline
- 2026-08-04: disclosed