CVE-2026-24218
published 2026-05-20CVE-2026-24218: NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed…
PriorityP348high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.59%
44.0th percentile
NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution, data tampering, escalation of privileges, information disclosure, and denial of service.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | dgx_spark | < OTA0 | OTA0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NVIDIA DGX Spark prior OTA0 SSH Host Key hard-coded key
vuldb·2026-05-20·CVSS 8.1
CVE-2026-24218 [HIGH] NVIDIA DGX Spark prior OTA0 SSH Host Key hard-coded key
A vulnerability labeled as critical has been found in NVIDIA DGX Spark. This impacts an unknown function of the component SSH Host Key Handler. Such manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is traded as CVE-2026-24218. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
GHSA
GHSA-849r-hj58-p84g: NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be dep
ghsa_unreviewed·2026-05-20
CVE-2026-24218 [HIGH] CWE-321 GHSA-849r-hj58-p84g: NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be dep
NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution, data tampering, escalation of privileges, information disclosure, and denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-20
Published