Report a Security Vulnerability

View as Markdown

Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

To report a potential security vulnerability in any NVIDIA product, please use either:

If reporting a potential vulnerability via email, please encrypt it using NVIDIA’s public PGP key (see PGP Key page) and include the following information:

  1. Product/Driver name and version/branch that contains the vulnerability
  2. Type of vulnerability (code execution, denial of service, buffer overflow, etc.)
  3. Instructions to reproduce the vulnerability
  4. Proof-of-concept or exploit code
  5. Potential impact of the vulnerability, including how an attacker could exploit the vulnerability

You may also use GitHub’s private vulnerability reporting on this repository (Security tab → Report a vulnerability) as an additional channel; PSIRT remains the fastest path to triage and tracking.

Refer to NVIDIA Security for past NVIDIA Security Bulletins and Notices.