ZeroHour

CVE-2026-61768

niche

Deserialization of Untrusted Data in NVIDIA Megatron Bridge

CVSS 3.1
7.8 high
EPSS
<1%p12
Published
()
Modified
AI analysis

NVIDIA Megatron Bridge, NVIDIA's open-source framework for training and post-training large language models within the NeMo ecosystem, contains a deserialization of untrusted data vulnerability (CWE-502). An attacker who can supply attacker-controlled serialized data to the framework — for example via untrusted training artifacts processed by a privileged or local user, per the CVSS local/low-privilege attack vector — can trigger unsafe deserialization. A successful exploit could result in arbitrary code execution, data tampering, and disclosure of sensitive information on the affected training system. Users of NVIDIA Megatron Bridge in ML engineering, research, and enterprise GPU training environments are affected. As of this writing there is no known exploitation in the wild, no public proof-of-concept, and CISA has not added it to the KEV catalog, with EPSS estimating only a 0.2% chance of exploitation in the next 30 days.

What to do: Check installed Megatron Bridge versions on training hosts and apply the patched release listed in NVIDIA's security advisory (version not specified in the data available here). Until patched, avoid deserializing or loading checkpoints, configs, or other serialized artifacts from untrusted or shared sources, and limit local access to systems running Megatron Bridge training jobs. Since exploitation requires attacker-controlled serialized input, review data ingestion paths and shared storage for untrusted model artifacts.

Affected
NVIDIA Nemo Megatron Bridge
Estimated exposure
nichelikely on the order of thousands of ML practitioners and training jobs on GPU clusters; not typically internet-exposed — Megatron Bridge is a specialized open-source LLM training/post-training library used inside GPU training environments rather than internet-facing deployments, so the plausible blast radius is bounded by its relatively niche ML-engineering…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendors
nvidia
Products
nemo megatron bridge
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.