CVE-2026-24231 Details
Description
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure.
A server-side request forgery (SSRF) vulnerability has been identified in NVIDIA NemoClaw, specifically within the validateEndpointUrl() component responsible for SSRF protection. This vulnerability allows an attacker to craft an endpoint URL that references the 0.0.0.0/8 address range, which can be delivered through a blueprint configuration file or a command-line interface (CLI) flag. Exploiting this vulnerability successfully may result in unauthorized information disclosure.
Users are advised to update to version 0.0.13 or later. The updated version can be downloaded from the NVIDIA NemoClaw GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvd.nist.gov/vuln/detail/CVE-2026-24231 | [email protected] | US Government Resource |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5837 | [email protected] | Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-24231 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nvidia nemoclaw | < 0.0.13 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | Initial Analysis | [email protected] |
| Apr 28, 2026 | New CVE Received | [email protected] |