ZeroHour

CVE-2026-61755

niche

Deserialization of Untrusted Data in NVIDIA Megatron Bridge

CVSS 3.1
7.8 high
EPSS
<1%p18
Published
()
Modified
AI analysis

NVIDIA Megatron Bridge, NVIDIA's open-source framework for large language model training built on the Megatron/NeMo stack, contains a deserialization-of-untrusted-data flaw (CWE-502). An attacker with low-privileged local access (per the CVSS vector AV:L/PR:L) who can cause the framework to deserialize attacker-controlled or otherwise untrusted data can trigger the flaw without user interaction. A successful exploit may result in arbitrary code execution, tampering with data, and disclosure of sensitive information on the affected training environment. Anyone running NVIDIA Megatron Bridge in development, research, or production ML training environments is potentially affected, though the local attack vector means systems are not exposed in the way internet-facing services are. As of this analysis there is no known public proof-of-concept, it is not in the CISA KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Inventory environments where Megatron Bridge is installed (training clusters, CI pipelines, researcher workstations) and upgrade to the fixed version listed in NVIDIA's security bulletin, since specific versions are not provided in this data. As an interim mitigation, avoid deserializing checkpoints, artifacts, or serialized inputs from untrusted or third-party sources, and restrict local access on shared or multi-tenant training systems.

Affected
NVIDIA Megatron Bridge (NeMo Megatron Bridge)
Estimated exposure
nichelikely thousands of developer/research/training environments, with no reliable public install-count basis — Megatron Bridge is a specialized, recently released LLM training framework used mainly by AI engineering and research teams rather than mass-market software, and the local (AV:L) attack vector limits practical exposure to environments that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendors
nvidia
Products
nemo megatron bridge
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.