Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Untrusted Data Deserialization in NVIDIA APEX Enabling Remote Code Execution |
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvidia
Nvidia apex |
|
| Vendors & Products |
Nvidia
Nvidia apex |
Tue, 24 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, data tampering, and information disclosure. | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: nvidia
Published:
Updated: 2026-03-25T03:56:14.756Z
Reserved: 2025-04-15T18:51:08.192Z
Link: CVE-2025-33244
Updated: 2026-03-24T20:53:28.703Z
Status : Awaiting Analysis
Published: 2026-03-24T21:16:24.437
Modified: 2026-03-25T15:41:58.280
Link: CVE-2025-33244
No data.
OpenCVE Enrichment
Updated: 2026-03-25T20:57:25Z