NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure.
{
"cwe_ids": [
"CWE-918"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24231.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "All versions prior to v0.0.13"
},
{
"last_affected": "All versions prior to v0.0.13"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "nvidia"
}{
"cpe": "cpe:2.3:a:nvidia:nemoclaw:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.0.13"
}
],
"source": "CPE_RANGE"
}