ZeroHour

CVE-2026-61759

niche

Deserialization of Untrusted Data in NVIDIA Megatron Bridge

CVSS 3.1
7.8 high
EPSS
<1%p18
Published
()
Modified
AI analysis

NVIDIA Megatron Bridge contains a deserialization-of-untrusted-data flaw (CWE-502), meaning the framework processes serialized input that an attacker can craft to execute unintended code paths. The CVSS vector (AV:L/PR:L/UI:N) indicates the attacker needs local access or low-level privileges, with no user interaction required — in practice, an attacker who can supply or tamper with a serialized artifact consumed by Megatron Bridge, such as a checkpoint or training input, could trigger the flaw. A successful exploit could result in arbitrary code execution, tampering with data, or disclosure of sensitive information on the system running the training workload. Affected users are AI engineering and research teams running NVIDIA Megatron Bridge (part of the NeMo/Megatron training ecosystem); the available data does not specify which version ranges are affected. Exploitation has not been observed: there is no public proof-of-concept, it is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Consult NVIDIA's PSIRT advisory for this CVE and upgrade Megatron Bridge to the fixed version it specifies (affected/fixed version numbers were not included in this data). Until patched, treat serialized artifacts from untrusted or shared sources — checkpoints, saved states, third-party model files — as untrusted input and avoid loading them into Megatron Bridge, and restrict execution environments where such files are processed. Since the vector is local with low privileges required, also audit who can write to shared storage or artifact pipelines feeding training jobs.

Affected
NVIDIA Megatron Bridge (NeMo Megatron Bridge)
Estimated exposure
nichelikely on the order of thousands of practitioner users at most (no published install counts) — Megatron Bridge is a specialized open-source training framework within NVIDIA's NeMo/Megatron ecosystem used primarily by AI teams running large-model training jobs, a deployment pattern with far smaller reach than general-purpose or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendors
nvidia
Products
nemo megatron bridge
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.