CVE-2026-24156Disclosure(nvidia / data_loading_library)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nvidia data_loading_library systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • data_loading_library

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
data_loading_library

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-07: 1Mentions · 2026-04-08: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 104-0704-08
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-081
Patch1
Full discourse2 posts
  • yousukezan@yousukezan
    Patch

    AI基盤を支えるNVIDIA製ソフトに深刻な脆弱性が見つかり、任意コード実行やサービス停止の危険が指摘された。機械学習パイプラインや推論基盤に影響し、攻撃されれば業務停止や不正操作につながる恐れがある。早急な更新対応が求められている。 NVIDIAの発表によると、CVE-2026-24156はNVIDIA DALIにおけるデシリアライズ処理の不備で、細工されたデータにより任意コード実行が可能となる高深刻度の脆弱性である。影響範囲は2.0未満の全バージョンに及ぶ。 またTriton Inference Serverでも複数の欠陥が修正され、CVE-2026-24173やCVE-2026-24174では不正リクエストによりサーバークラッシュが発生し、サービス拒否攻撃が成立する。その他にも入力検証不備や情報漏えいの問題が含まれる。 これらの脆弱性はAI運用基盤に直結するため、影響は広範囲に及ぶ可能性がある。DALIはv2.0以降、Tritonはr26.02以降への更新が推奨されており、未対応環境では優先的な対策が必要とされる。 https://securityonline.info/nvidia-dali-triton-security-update-cve-2026-24156/

    Post summary

    NVIDIA disclosed multiple critical vulnerabilities (CVE‑2026‑24156, 24173, 24174) in DALI and Triton that enable arbitrary code execution or denial‑of‑service; urgent updates to v2.0 and r26.02 are advised to mitigate these risks.

    040842.3K
    14.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24156 NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbit… https://www.cve.org/CVERecord?id=CVE-2026-24156

    Post summary

    The snippet announces CVE-2026-24156 as a deserialization vulnerability in NVIDIA DALI that could lead to arbitrary execution, but it provides no PoC, exploit details, patch info, or evidence of active exploitation.

    00100435
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnvidiadata_loading_library---

Explore more