NVIDIA Dynamo: Deserialization of untrusted data in Dynamo reaches denial of service and data tampering
CVE-2026-47623NVIDIA / GPU stackcurated
Impact
Deserialization of untrusted data in Dynamo reaches denial of service and data tampering from an unauthenticated network caller, scored 8.2. Dynamo is NVIDIA's disaggregated serving framework, so this sits on the request path of a production inference tier.
Who can reach it
Network, unauthenticated, no user interaction. Any client that can submit to the Dynamo endpoint.
What to do
Upgrade Dynamo per bulletin 5842 and roll the deployment. Cost: rolling restart of the serving tier; no driver or firmware change. Verify the endpoint is not exposed beyond the mesh.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.