Executive brief
NVIDIA Dynamo for Linux is a component used for handling multimodal media processing on Linux systems. A server-side request forgery (SSRF) vulnerability in its Rust-based media fetcher could allow an attacker to trick the server into making unintended network requests to internal or external systems, potentially leading to unauthorized access to sensitive information or services.
Technical details
The vulnerability is a server-side request forgery (SSRF) flaw located in the Rust multimodal media fetcher component of NVIDIA Dynamo for Linux. An attacker can manipulate the media fetcher to send HTTP requests to arbitrary internal or external systems, bypassing network access controls. The attack is network-reachable and does not require authentication. Successful exploitation enables information disclosure from internal services or systems. The affected product and specific patched versions are not detailed in the advisory.
Affected products
- NVIDIA Dynamo for Linux
Timeline
- 2026-08-04: disclosed