CVE-2026-65179: High severity Nvidia NeMo vulnerability
Published Sep 22, 2026
·Updated
NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.
Affected Software
1 affected component
Nvidia NeMo
Event History
Sep 22, 2026
CVE Published
via MITRE·02:04 PM
Data Sourced
via MITRE·02:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
An attacker must cause an affected TabularTokenizer instance to deserialize an attacker-controlled .pkl file. Exploitation requires user interaction, while the attacker does not need prior privileges.
2
What are the potential consequences of successful exploitation?
Successful exploitation may allow code execution, data tampering, denial of service, and information disclosure. The vulnerability is rated high severity with a CVSS score of 8.8.