CVE-2026-0481
CVE-2026-0481 is a critical-severity vulnerability with a CVSS 4.0 base score of 9.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1327.
Key facts
- Severity: Critical (CVSS 4.0 base score 9.2)
- EPSS exploit prediction: 0% (24th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-30502
- Weakness: CWE-1327
- Published:
- Last modified:
Description
Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability
Frequently asked questions
- What is CVE-2026-0481?
- Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability
- How severe is CVE-2026-0481?
- CVE-2026-0481 has a CVSS 4.0 base score of 9.2, rated critical severity.
- Is CVE-2026-0481 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (24th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-0481?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2026-0481 have an EU (EUVD) identifier?
- Yes. CVE-2026-0481 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-30502.
- When was CVE-2026-0481 published?
- CVE-2026-0481 was published on 2026-05-15 and last updated on 2026-06-17.
References
Other CWE-1327 vulnerabilities
- CVE-2025-61934 — Critical (CVSS 10.0): A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19.…
- CVE-2023-1968 — Critical (CVSS 10.0): Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An…
- CVE-2026-24015 — Critical (CVSS 9.8): A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before…
- CVE-2026-42503 — High (CVSS 8.8): gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If…
- CVE-2026-47873 — High (CVSS 8.0): The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network…
- CVE-2025-55322 — High (CVSS 7.3): Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.