Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nv-tlabs
Nv-tlabs gen3c |
|
| Vendors & Products |
Nv-tlabs
Nv-tlabs gen3c |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process. | |
| Title | NVIDIA SIL GEN3C Unauthenticated RCE via Pickle Deserialization in Inference API | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T16:16:47.007Z
Reserved: 2026-06-10T20:14:32.829Z
Link: CVE-2026-53805
Updated: 2026-06-17T18:12:52.414Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:57:15Z