NVIDIA Dynamo for Linux: 15 Vulnerabilities Including Critical Flaws Disclosed Together
Key findings • 15 vulnerabilities disclosed simultaneously for NVIDIA Dynamo for Linux on August 4, 2026. • Critical vulnerability CVE-2026-24254 allows code execution, privilege escalation, …

Key findings
- 15 vulnerabilities disclosed simultaneously for NVIDIA Dynamo for Linux on August 4, 2026.
- Critical vulnerability CVE-2026-24254 allows code execution, privilege escalation, and more.
- Multiple high-severity SSRF flaws in multimodal components could lead to information disclosure.
- Vulnerabilities include out-of-bounds writes, race conditions, and deserialization issues.
- Affected components range from media fetchers to examples and recipes.
On August 4, 2026, NVIDIA disclosed a batch of 15 vulnerabilities affecting its Dynamo for Linux product. The vulnerabilities, all disclosed on the same day, span a range of severities from medium to critical, with several high-severity flaws related to server-side request forgery (SSRF) and out-of-bounds writes. The most severe issue, CVE-2026-24254, carries a critical CVSSv3 score of 9.8 and could lead to code execution, privilege escalation, data tampering, denial of service, and information disclosure.
Several vulnerabilities are grouped by their attack vector or affected component. A significant cluster of high-severity vulnerabilities (CVE-2026-47614, CVE-2026-47615, CVE-2026-47616, CVE-2026-47617, CVE-2026-47618) relate to server-side request forgery (SSRF) within the multimodal media fetcher or through crafted multimodal requests. These SSRF flaws could allow attackers to disclose sensitive information.
Other vulnerabilities include an out-of-bounds write (CVE-2026-24253) with high severity, and a critical out-of-bounds write (CVE-2026-24254) that presents the broadest impact. Additionally, race conditions in the LoRA manager singleton initialization (CVE-2026-47621, CVE-2026-47620) could lead to denial of service and data tampering. A deserialization of untrusted data vulnerability (CVE-2026-47623) also poses a risk of denial of service and data tampering. The examples and recipes component of Dynamo for Linux is affected by a vulnerability (CVE-2026-47619) that could result in system failure, with potential impacts including code execution, data tampering, denial of service, and information disclosure.
The disclosures also highlight issues with improper limitation of pathname to restricted directories (CVE-2026-47613, CVE-2026-47612), potentially leading to information disclosure. A hash collision vulnerability in the multimodal embedding cache (CVE-2026-24255) could result in data tampering. Finally, a vulnerability allowing generation of error messages with sensitive information (CVE-2026-47622) could lead to information disclosure.
NVIDIA has addressed these vulnerabilities, and users are advised to update to the latest available version of Dynamo for Linux to mitigate these risks. The comprehensive nature of this batch underscores the importance of timely patching for complex software like NVIDIA Dynamo. Users should review the specific CVE details to understand the potential impact on their deployments and prioritize updates accordingly.
The simultaneous disclosure of these 15 vulnerabilities emphasizes the need for prompt attention from system administrators managing NVIDIA Dynamo for Linux. The range of impacts, from denial of service to code execution and information disclosure, necessitates a thorough assessment of affected systems and the application of patches as soon as possible. Staying informed about vendor security advisories and applying updates promptly are crucial steps in maintaining a secure environment.