Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
All versions prior to 2.7.2
affected
Description
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
All versions prior to 2.7.2
References
nvd.nist.gov/vuln/detail/CVE-2026-24186
www.cve.org/CVERecord?id=CVE-2026-24186
nvidia.custhelp.com/app/answers/detail/a_id/5819