PYSEC-2026-695

    Dashboard / Vulnerabilities / PYSEC-2026-695

    PYSEC-2026-695

    Published: 2 Jul 2026Last Modified: 6 Jul 2026

    Summary: Allocation of Resources Without Limits or Throttling in nvflare

    Details: ### Impact NVIDIA FLARE contains a vulnerability in Admin Interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable All versions before 2.0.16 are affected. ### Patches The patch will be included in nvflare==2.0.16. ### Workarounds The changes in commits https://github.com/NVIDIA/NVFlare/commit/93588b3a0dff9bd4568983071b74d8b420de3a6e and https://github.com/NVIDIA/NVFlare/commit/93588b3a0dff9bd4568983071b74d8b420de3a6e can be applied to any version of the NVIDIA FLARE without any adverse effect. ### Additional information Issue Found on: 2022.3.3 Issue Found by: Oliver Sellwood (@Nintorac)

    Affected packages

    Package

    Name: nvflare

    Purl: pkg:pypi/nvflare

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.0.16

    Affected versions

    0.1.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2026-695 | CVE-DB