CVE-2026-61765
nicheInsecure Deserialization Flaw in NVIDIA Megatron Bridge
NVIDIA Megatron Bridge, an LLM post-training/fine-tuning library in the NVIDIA NeMo ecosystem, contains a deserialization-of-untrusted-data vulnerability (CWE-502). Per the CVSS vector (local attack vector, low privileges required, no user interaction), exploitation requires an attacker with local or low-privileged access who can get untrusted serialized data deserialized by the software, such as a malicious checkpoint or artifact processed during a training job. A successful exploit could lead to arbitrary code execution, tampering with data, and disclosure of sensitive information on the affected training host. Affected users are ML engineering and research teams running Megatron Bridge; the source data does not specify which version ranges are affected, so defenders must consult NVIDIA's advisory. There is no known exploitation, no public proof-of-concept, and it is not in CISA KEV, with EPSS estimating only a 0.2% probability of exploitation in the next 30 days.
What to do: Check installed Megatron Bridge versions against NVIDIA's security advisory and upgrade to the fixed release it identifies. Until patching, only deserialize model checkpoints and other serialized artifacts from trusted sources, and limit local/low-privileged access to hosts running Megatron Bridge training jobs.
| NVIDIA Megatron Bridge (NeMo Megatron Bridge) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- Vendors
- nvidia
- Products
- nemo megatron bridge
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.