6.4

CVE-2026-24220

NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nvidia ≫ Tensorrt-llm Version <= 1.3.0
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc0
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc1
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc10
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc11
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc2
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc3
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc4
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc5
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc6
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc7
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc8
Nvidia ≫ Tensorrt-llm Version 1.3.0 Update rc9
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.124
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Nvidia 6.4 0.5 5.9
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://nvd.nist.gov/vuln/detail/CVE-2026-24220
US Government Resource
https://www.cve.org/CVERecord?id=CVE-2026-24220
Third Party Advisory