CVE-2026-24186
published 2026-04-28CVE-2026-24186: NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.48%
38.1th percentile
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | flare_sdk | — | — |
| nvidia | nvflare | < 2.7.2 | 2.7.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3468-q87c-9xhv: NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded
ghsa_unreviewed·2026-04-28
CVE-2026-24186 [HIGH] CWE-502 GHSA-3468-q87c-9xhv: NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.
VulDB
NVIDIA FLARE SDK Encoded Message deserialization
vuldb·2026-04-28·CVSS 8.8
CVE-2026-24186 [HIGH] NVIDIA FLARE SDK Encoded Message deserialization
A vulnerability was found in NVIDIA FLARE SDK. It has been declared as very critical. Impacted is an unknown function of the component Encoded Message Handler. Such manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2026-24186. The attack can be launched remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-28
Published