CVE-2026-24204: NVIDIA Nvflare

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.

Affected products

  • NVIDIA Nvflare: before 2.7.2 (fixed in 2.7.2)

Published 2026-04-28. Last modified 2026-06-17.