These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
According to the supplied official NVD and NVIDIA PSIRT metadata, CVE-2026-24207 is a critical authentication-bypass issue in NVIDIA Triton Inference Server. The supplied CVSS vector indicates a network-reachable, unauthenticated attack path with no user interaction and high impact to confidentiality, integrity, and availability (9.8). The vulnerable CPE evidence in the corpus points to Triton Inference S [truncated]
CVE-2026-24206 is a high-severity authentication-bypass vulnerability in NVIDIA Triton Inference Server. NVD rates it 7.3 with a network attack vector, low complexity, and no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). NVIDIA identifies CWE-288, and the affected range in the NVD record is Triton Inference Server versions before 26.03. In practical terms, an expo [truncated]
CVE-2026-24163 is a HIGH-severity NVIDIA TensorRT-LLM issue caused by unsafe deserialization in RPC testing. The published NVD data ties the flaw to CWE-502 and indicates vulnerable TensorRT-LLM versions ending before 1.2. If exploited, the impact can include code execution, denial of service, data tampering, and information disclosure.
CVE-2026-24160 is a medium-severity vulnerability in NVIDIA TRT-LLM for any platform. An attacker could trigger an unchecked return value that leads to a null pointer dereference, which may cause denial of service. The supplied NVD data maps affected versions to NVIDIA TRT-LLM releases before 1.2.
CVE-2026-24142 is a medium-severity NVIDIA TensorRT-LLM vulnerability involving unsafe deserialization and an unsafe serialized handle. According to the supplied NVD record, a successful exploit may lead to code execution, data tampering, and information disclosure. The issue is scoped to TensorRT-LLM versions prior to 1.2 in the provided CPE criteria and is rated CVSS 6.3.
CVE-2025-33255 describes an unsafe deserialization weakness in the MPI server component of NVIDIA TRT-LLM. NVIDIA’s advisory and the NVD record identify the issue as CWE-502 and mark TRT-LLM versions before 1.2 as vulnerable. The published CVSS v3.1 score is 7.5 (HIGH), with potential impact including code execution, denial of service, data tampering, and information disclosure.
CVE-2026-24156 is a HIGH severity vulnerability in NVIDIA's Data Loading Library (DALI) that allows deserialization of untrusted data, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 7.3 and is classified as HIGH severity. Security teams and administrators responsible for NVIDIA Data Loading Library (DALI) deployments should prioritize patching this vulnerability to [truncated]
CVE-2026-24165 is a high-severity vulnerability in NVIDIA BioNeMo that allows deserialization of untrusted data, potentially leading to code execution, denial of service, information disclosure, and data tampering. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. This vulnerability exists in the NVIDIA BioNeMo Framework, specifically in the deserialization process. An attacker co [truncated]
CVE-2026-24164 is a high-severity vulnerability in NVIDIA BioNeMo that allows deserialization of untrusted data, potentially leading to code execution, denial of service, information disclosure, and data tampering. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Affected organizations should prioritize patching to prevent potential impacts on confidentiality, integrity, and availability.
NVIDIA Jetson Linux has a vulnerability in initrd, where an unprivileged attacker with physical access could inject incorrect command line arguments. This vulnerability could lead to code execution, escalation of privileges, denial of service, data tampering, and information disclosure. The vulnerability is tracked as CVE-2026-24154 and has a CVSS score of 7.6, indicating high severity. Affected users sho [truncated]
CVE-2026-24148 is a high-severity vulnerability in NVIDIA Jetson for JetPack, caused by an insecure default in the system initialization logic. This vulnerability could lead to information disclosure, data tampering, and partial denial of service across devices sharing the same machine ID. The vulnerability affects users of NVIDIA Jetson for JetPack, and organizations using this product should prioritize [truncated]
CVE-2025-33239 is a high-severity vulnerability in NVIDIA Megatron Bridge, a component of the NVIDIA Nemo Megatron Bridge product. The vulnerability is caused by a code injection issue in a data merging tutorial, which could allow an attacker to execute arbitrary code, escalate privileges, disclose information, and tamper with data. The Common Vulnerability Scoring System (CVSS) score for this vulnerabili [truncated]