CVE-2026-24189Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-21: 3Mentions · 2026-04-22: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-21: 304-2104-22
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-213
Disclosure3
2026-04-221
Patch1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    NVIDIA patches critical flaws in KAI Scheduler and CUDA-Q. CVE-2026-24189 and CVE-2026-24177 risk data leaks and DoS. Secure your GPU workloads—update today! #NVIDIA #GPUSecurity #CUDA #InfoSec #CyberSecurity #PatchAlert https://securityonline.info/nvidia-kai-scheduler-cuda-q-security-vulnerabilities-patch/ https://t.co/ASwEVrCXOq

    Post summary

    The tweet announces that NVIDIA has released patches for two critical CVEs affecting KAI Scheduler and CUDA‑Q, urging users to update to mitigate data leak and DoS risks.

    12031673
    12.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24189 NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A… https://www.cve.org/CVERecord?id=CVE-2026-24189

    Post summary

    The post offers a brief disclosure of a vulnerability in NVIDIA CUDA‑Q that allows an unauthenticated attacker to cause an out‑of‑bounds read with a crafted request, but provides no PoC, exploit, or mitigation details.

    00010151
    57.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-24189 NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds r… CVSS 8.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-24189 #NVIDIA #CyberSecurity #InfoSec

    Post summary

    The tweet announces CVE-2026-24189 as an unauthenticated out-of-bounds vulnerability in NVIDIA CUDA-Q with CVSS 8.2, linking to a detailed analysis, but provides no PoC, exploit, or patch information.

    000006
    124 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24189 NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A… https://www.cve.org/CVERecord?id=CVE-2026-24189 ----- Traducción: CVE-2026-24189 NVI… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑24189, noting it allows an unauthenticated out‑of‑bounds read in NVIDIA CUDA‑Q, but no PoC, exploit, or mitigation is provided.

    0000025
    72 followersView on X

Explore more