CVE-2026-24231: SSRF
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24231?
CVE-2026-24231 is classified as a high-severity vulnerability due to its potential to facilitate server-side request forgery.
How do I fix CVE-2026-24231?
To fix CVE-2026-24231, ensure that the validation of endpoint URLs in the configuration files or CLI flags is properly implemented to block access to the 0.0.0.0/8 address range.
Who is affected by CVE-2026-24231?
CVE-2026-24231 affects users of NVIDIA NemoClaw software versions that do not have the patched validation mechanism in place.
What is server-side request forgery in the context of CVE-2026-24231?
In the context of CVE-2026-24231, server-side request forgery allows an attacker to manipulate the server to send requests to unintended internal endpoints.
When was CVE-2026-24231 disclosed?
CVE-2026-24231 was disclosed as a vulnerability in NVIDIA NemoClaw but the specific disclosure date is not provided in the summary.