Skip to main content

Vendor/product archive

nvidia / nvflare CVEs

Beta · best-effort

6 CVEs tagged to nvidia / nvflare4 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-24204

Published Apr 28, 2026

NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to infor…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24186

Published Apr 28, 2026

NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploi…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24178

Published Apr 28, 2026

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-co…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2022-34668

Published Aug 29, 2022

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31605

Published Jul 1, 2022

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Unt…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31604

Published Jul 1, 2022

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The d…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1