CVE-2026-24255
Received Received - Intake

NVIDIA Dynamo Linux Hash Collision Vulnerability

Vulnerability report for CVE-2026-24255, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: NVIDIA Corporation

Description

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nvidia dynamo_for_linux to 1.1.0 (inc)
nvidia dynamo *-*

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1023 The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NVIDIA Dynamo for Linux has a flaw in its multimodal embedding cache. An attacker can exploit this by submitting images that have the same pixel byte sequence but different dimensions, causing a hash collision. This may allow data tampering as a result.

Detection Guidance

Detection involves monitoring for unusual image submissions or cache inconsistencies. Check Dynamo logs for hash collisions or tampered data. Inspect cache directories for images with identical pixel data but varying dimensions.

Impact Analysis

This vulnerability could allow an attacker to alter data processed by NVIDIA Dynamo for Linux. Since the impact is on integrity (I:H in CVSS), tampered data might go undetected, potentially affecting decisions or systems relying on this data.

Mitigation Strategies

Update NVIDIA Dynamo for Linux to the latest version beyond v1.1.0. Disable or restrict access to the multimodal embedding cache if not required. Implement input validation for image submissions to prevent hash collisions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24255. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart