Executive brief
NVIDIA Dynamo is a multimodal platform for Linux that processes media content. A DNS rebinding vulnerability in its media fetcher component could allow an attacker to trick the server into making requests to internal systems or unauthorized external services, potentially exposing sensitive information on networks where Dynamo is deployed.
Technical details
The vulnerability is a server-side request forgery (SSRF) flaw in NVIDIA Dynamo's multimodal media fetcher, exploitable via DNS rebinding attacks. An attacker can manipulate DNS responses to cause the server to access unintended internal resources or services. The attack requires network access to influence DNS resolution, but no authentication is needed. Successful exploitation leads to information disclosure from internal systems or metadata accessible from the server's network context. Patches should be available from NVIDIA's security advisories.
Affected products
- NVIDIA Dynamo <UNKNOWN>
Timeline
- 2026-08-04: disclosed