CVE-2026-24255

Summary

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.

Affected Software

VendorProductVersion RangeStatus
NVIDIADynamo0 to v1.1.0affected

Weaknesses

  • CWE-1023: CWE-1023 Incomplete Comparison with Missing Factors

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References