Unauthenticated Endpoint Vulnerability in NVIDIA CUDA-Q
CVE-2026-24189

8.2HIGH

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-24189?

NVIDIA CUDA-Q features a vulnerability in an endpoint that allows unauthenticated attackers to send specially crafted requests. This could result in an out-of-bounds read, leading to potential denial of service and unintended information disclosure. Proper measures should be taken to patch affected systems and safeguard data integrity and availability.

Affected Version(s)

CUDA-Q All All versions prior to 0.14.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.