CVE-2026-65085
CVE-2026-65085 is a medium-severity vulnerability in Nvidia Openshell with a CVSS 3.x base score of 5.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-116.
Key facts
- Severity: Medium (CVSS 3.x base score 5.2)
- EPSS exploit prediction: 0% (2nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-116
- Affected product: Nvidia Openshell
- Published:
- Last modified:
Description
NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
Frequently asked questions
- What is CVE-2026-65085?
- NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
- How severe is CVE-2026-65085?
- CVE-2026-65085 has a CVSS 3.x base score of 5.2, rated medium severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-65085 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (2nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-65085?
- CVE-2026-65085 affects Nvidia Openshell. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-65085?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-65085 published?
- CVE-2026-65085 was published on 2026-08-25 and last updated on 2026-09-03.
References
- https://github.com/NVIDIA/product-security/tree/main/2026/5872
- https://nvd.nist.gov/vuln/detail/CVE-2026-65085
- https://www.cve.org/CVERecord?id=CVE-2026-65085
Affected products (1)
- cpe:2.3:a:nvidia:openshell:*:*:*:*:*:*:*:*
More vulnerabilities in Nvidia Openshell
- CVE-2026-65093 — Critical (CVSS 9.9): NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful…
- CVE-2026-65083 — Critical (CVSS 9.9): NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an…
- CVE-2026-65091 — High (CVSS 8.8): NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection.…
- CVE-2026-65092 — High (CVSS 8.5): NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7…
- CVE-2026-65086 — Medium (CVSS 6.8): NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS…
All CVEs affecting Nvidia Openshell →
Other CWE-116 vulnerabilities
- CVE-2025-55730 — Critical (CVSS 10.0): XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in…
- CVE-2025-55729 — Critical (CVSS 10.0): XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in…
- CVE-2023-47143 — Critical (CVSS 10.0): IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection,…
- CVE-2023-26472 — Critical (CVSS 9.9): XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with…
- CVE-2022-41934 — Critical (CVSS 9.9): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with…
- CVE-2022-36100 — Critical (CVSS 9.9): XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform.…