


Perceptive Security
SOC/SIEM Consultancy

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that sha…
Published:
3 augustus 2026 om 22:00:00
Alert date:
4 augustus 2026 om 19:04:59
Source:
nvd.nist.gov
Emerging Technologies, Enterprise Applications
CVE-2026-24255 affects NVIDIA Dynamo for Linux, specifically in its multimodal embedding cache component. The vulnerability allows an attacker to trigger a hash collision by submitting images that share identical pixel byte sequences but differ in dimensions. This flaw in the hashing mechanism can be exploited to cause data tampering. The vulnerability resides in the AI/ML inference serving framework NVIDIA Dynamo. No authentication bypass or remote code execution is mentioned, but data integrity is at risk. NVIDIA has published a security advisory through their product-security GitHub repository. The CVE is currently in 'Received' status at NVD, indicating it is newly submitted. Users of NVIDIA Dynamo on Linux systems should monitor for patches and apply mitigations as they become available.
Technical details
Mitigation steps:
Affected products:
NVIDIA Dynamo for Linux
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-24255
https://github.com/NVIDIA/product-security/tree/main/2026/5842
https://www.cve.org/CVERecord?id=CVE-2026-24255
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
