Junglewise Threat Intelligence

CVE-2026-47618: NVIDIA Dynamo for Linux server-side request forgery in Rust multimodal media fetcher

CVE-2026-47618 · Severity: high · CVSS 7.5 · Published 2026-08-04

Technologies: Nvidia Dynamo for Linux, Nvidia Dynamo, Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA Dynamo for Linux is a component used for handling multimodal media processing on Linux systems. A server-side request forgery (SSRF) vulnerability in its Rust-based media fetcher could allow an attacker to trick the server into making unintended network requests to internal or external systems, potentially leading to unauthorized access to sensitive information or services.

Technical details

The vulnerability is a server-side request forgery (SSRF) flaw located in the Rust multimodal media fetcher component of NVIDIA Dynamo for Linux. An attacker can manipulate the media fetcher to send HTTP requests to arbitrary internal or external systems, bypassing network access controls. The attack is network-reachable and does not require authentication. Successful exploitation enables information disclosure from internal services or systems. The affected product and specific patched versions are not detailed in the advisory.

Affected products

  • NVIDIA Dynamo for Linux

Timeline

  • 2026-08-04: disclosed

References

Related threats