ZeroHour

CVE-2026-61751

niche

Unsafe deserialization of untrusted data in NVIDIA Megatron Bridge

CVSS 3.1
7.8 high
EPSS
<1%p18
Published
()
Modified
AI analysis

NVIDIA Megatron Bridge contains a deserialization-of-untrusted-data flaw (CWE-502): when the software deserializes data it does not control or verify, an attacker can craft that data to execute code. The CVSS vector indicates the attacker needs local access and low privileges, with no user interaction required, which is consistent with processing attacker-influenced serialized inputs such as model artifacts loaded into the framework. A successful exploit could allow code execution, tampering with data, and disclosure of sensitive information on the affected host. Anyone running NVIDIA Megatron Bridge (part of the NVIDIA NeMo ecosystem) is potentially affected, especially users who deserialize data from untrusted or third-party sources. Exploitation has not been reported: there is no known public PoC, it is not in the CISA KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Check NVIDIA's security advisory for CVE-2026-61751 and upgrade Megatron Bridge to the patched release it specifies (no fixed version is stated in the data available here). Until patched, avoid deserializing checkpoints or other serialized data from untrusted or third-party sources, and audit training/conversion pipelines that load externally supplied model artifacts on shared or multi-tenant hosts.

Affected
nvidia NeMo Megatron Bridge
Estimated exposure
nicheon the order of thousands of users/deployments at most; likely fewer in production — Megatron Bridge is a recently introduced, specialized Python library in the NVIDIA NeMo ecosystem for LLM training/checkpoint workflows, used by ML engineers rather than mass-deployed software, and no public install-count or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendors
nvidia
Products
nemo megatron bridge
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.