ZeroHour

CVE-2026-61761

niche

Local Unsafe Deserialization of Untrusted Data in NVIDIA Megatron Bridge

CVSS 3.1
7.8 high
EPSS
<1%p18
Published
()
Modified
AI analysis

NVIDIA Megatron Bridge, a library in NVIDIA's NeMo/Megatron ecosystem for large language model training and post-training, contains a deserialization of untrusted data vulnerability (CWE-502). According to the CVSS vector (AV:L/PR:L/UI:N), an attacker with local access and low privileges can trigger the flaw without user interaction by causing the software to deserialize untrusted data. A successful exploit could yield code execution, tampering with data, and disclosure of sensitive information, with the impact rated high across confidentiality, integrity, and availability. Anyone running Megatron Bridge in development or training environments is potentially affected; because the attack vector is local, it is not exposed like an internet-facing service, limiting realistic exposure to hosts where the library is used. There is currently no known public proof-of-concept, no confirmed exploitation in the wild, and a low predicted exploitation probability (EPSS 0.3%, percentile 18).

What to do: Upgrade Megatron Bridge to the fixed release named in NVIDIA's security bulletin (the specific version numbers are not included in the available data, so verify against NVIDIA PSIRT's advisory). Until patched, restrict local access to hosts running Megatron Bridge, avoid deserializing untrusted or third-party checkpoints and serialized data, and check whether your training pipelines load externally supplied serialized artifacts. As the vector is local, standard host privilege hygiene and limiting who can run jobs in training environments reduce risk.

Affected
NVIDIA Megatron Bridge (NeMo Megatron Bridge)
Estimated exposure
nicheunknown; plausibly on the order of thousands of developer/training environments worldwide (no published install counts) — No public install counts or internet-exposure scans exist for Megatron Bridge; because the flaw requires local low-privileged access, exposure is bounded by the number of teams using this specialized LLM training library in training jobs…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendors
nvidia
Products
nemo megatron bridge
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.