CVE-2026-24255CWE-1023

CVE-2026-24255

High · published August 4, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
31.6
In the wild
Unconfirmed
What it is

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00384 · 31.6th percentile
Weakness
CWE-1023 · Incomplete Comparison with Missing Factors
Published
2026-08-04T22:16Z
Affected products (1)
ProductVersionsFixed in
nvidia/dynamo≤ 1.1.0
References (3)
EPSS history
Timeline
  • 04 AUG 17:23Z
    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that…
    cvelistv5