cbcvebase.
CVE-2026-24231
published 2026-04-28

CVE-2026-24231: NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by…

PriorityP428medium6.3CVSS 3.1
AVLACLPRNUIRSCCHINAN
EPSS
0.13%
2.8th percentile
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure.

Affected

2 ranges
VendorProductVersion rangeFixed in
nvidianemoclaw< 0.0.130.0.13
nvidianemoclaw
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.