ZeroHour

CVE-2026-61758

niche

Deserialization of Untrusted Data in NVIDIA Megatron Bridge

CVSS 3.1
7.8 high
EPSS
<1%p12
Published
()
Modified
AI analysis

NVIDIA Megatron Bridge contains a deserialization-of-untrusted-data flaw (CWE-502) that could allow an attacker who can supply attacker-controlled data for deserialization to achieve code execution, data tampering, or information disclosure. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N) indicates the attack is local in scope, requires low privileges, and needs no user interaction, so risk concentrates in environments where the framework deserializes untrusted data, such as serialized artifacts or inputs loaded by training pipelines. A successful exploit yields high impact to confidentiality, integrity, and availability within the affected process, potentially giving the attacker arbitrary code execution on the training host. Only users of NVIDIA Megatron Bridge, the NeMo/Megatron training framework, are affected, and the available data does not specify affected version ranges, so operators should consult NVIDIA's PSIRT advisory. Exploitation has not been observed: there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at roughly 0.2%.

What to do: Update Megatron Bridge to the latest release per NVIDIA's advisory, verifying affected and fixed versions against the NVIDIA PSIRT advisory since the available data does not list them. Until patched, only deserialize data from trusted sources and restrict which users or processes can supply serialized inputs to training jobs. Teams running Megatron Bridge on shared or multi-tenant training hosts should treat local code execution as a lateral-movement risk and prioritize updating.

Affected
NVIDIA Megatron Bridge (NeMo Megatron Bridge)
Estimated exposure
nichelikely low thousands of installations at most (niche developer/training framework; estimate, no public install counts) — Megatron Bridge is a specialized training/fine-tuning framework deployed by ML teams on internal training infrastructure rather than as an internet-facing service, and no public adoption or install counts exist, so the population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendors
nvidia
Products
nemo megatron bridge
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.