CVE-2026-61767
nicheDeserialization of Untrusted Data in NVIDIA Megatron Bridge
NVIDIA Megatron Bridge contains a deserialization-of-untrusted-data flaw (CWE-502) in which the library processes serialized input without adequate validation, allowing an attacker to craft malicious serialized data that is then deserialized. Per the CVSS vector (AV:L/PR:L/UI:N), exploitation requires local access with low privileges and no user interaction, consistent with loading untrusted serialized artifacts such as training checkpoints on a shared or multi-tenant machine. A successful exploit could yield arbitrary code execution, data tampering, and disclosure of sensitive information such as model weights or training data, with high impact on confidentiality, integrity, and availability. Anyone using NVIDIA Megatron Bridge is affected; the specific affected and fixed version ranges are not included in the available data, so the NVIDIA advisory should be consulted. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at only about 0.2%.
What to do: Check NVIDIA's security advisory for the exact affected and fixed versions and upgrade Megatron Bridge to the patched release it specifies (not stated in this data). Until patched, avoid deserializing checkpoints or other serialized files from untrusted sources and restrict unprivileged write access on shared or multi-tenant training hosts, since the flaw requires local access with low privileges. No active exploitation is known, so this can be handled in the normal patching cycle.
| NVIDIA NeMo Megatron Bridge | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- Vendors
- nvidia
- Products
- nemo megatron bridge
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.