Medium severity6.3NVD Advisory· Published Apr 28, 2026· Updated May 4, 2026
CVE-2026-24231
CVE-2026-24231
Description
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- nvidia.custhelp.com/app/answers/detail/a_id/5837nvdVendor Advisory
- www.cve.org/CVERecordnvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2026-24231nvdUS Government Resource
News mentions
0No linked articles in our index yet.