ZeroHour

CVE-2026-61752

niche

Deserialization of Untrusted Data in NVIDIA Megatron Bridge

CVSS 3.1
7.8 high
EPSS
<1%p18
Published
()
Modified
AI analysis

NVIDIA Megatron Bridge, NVIDIA's framework for training and fine-tuning large language models, contains a deserialization-of-untrusted-data flaw (CWE-502). The attack vector is local (CVSS:3.1/AV:L/PR:L/UI:N), so an attacker needs low-privileged access to a machine or pipeline where the framework processes serialized data it did not create, such as externally supplied checkpoints or model artifacts. A successful exploit could allow the attacker to execute code, tamper with data, and disclose information on the affected system. Risk applies to organizations running Megatron Bridge in ML development or training environments, particularly where untrusted model files are loaded. There is no known public proof of concept, it is not in the CISA KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, so no exploitation is currently known.

What to do: Check NVIDIA's PSIRT advisory (CVE-2026-61752) for the patched Megatron Bridge release and upgrade training environments when the fix is published. As interim mitigation, avoid deserializing checkpoints or serialized artifacts from untrusted sources, and limit low-privileged local access to hosts and CI pipelines that run Megatron Bridge. Audit whether your training or fine-tuning workflows load externally supplied model files.

Affected
NVIDIA NeMo Megatron Bridge
Estimated exposure
nicheunknown, plausibly thousands of ML engineering/training environments at most — Megatron Bridge is a specialized open-source AI training framework used by machine learning teams rather than internet-facing services, and no public install counts or internet-exposure scan data are available, so only a low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendors
nvidia
Products
nemo megatron bridge
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.