Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 04 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nvidia:nemoclaw:*:*:*:*:*:*:*:* |
Wed, 29 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Apr 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvidia
Nvidia nemoclaw |
|
| Vendors & Products |
Nvidia
Nvidia nemoclaw |
Wed, 29 Apr 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NVIDIA NemoClaw SSRF Vulnerability via Endpoint URL |
Tue, 28 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: nvidia
Published:
Updated: 2026-04-29T15:11:36.521Z
Reserved: 2026-01-21T19:09:37.972Z
Link: CVE-2026-24231
Updated: 2026-04-29T14:13:55.625Z
Status : Analyzed
Published: 2026-04-28T19:36:45.637
Modified: 2026-05-04T14:30:50.063
Link: CVE-2026-24231
No data.
OpenCVE Enrichment
Updated: 2026-04-29T10:10:29Z