CVE Vulnerabilities

CVE-2025-33194

Incorrect Behavior Order: Validate Before Canonicalize

Published: Nov 25, 2025 | Modified: Dec 02, 2025
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful exploit of this vulnerability might lead to information disclosure or denial of service.

Weakness

The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Affected Software

NameVendorStart VersionEnd Version
Dgx_osNvidia- (including)- (including)

Potential Mitigations

References