Vulnerability Bulletins

CVE-2026-65179

   
Affected software NVIDIA
 
NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-65179