Report a Security Vulnerability
Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
To report a potential security vulnerability in any NVIDIA product, please use either:
- This web form: Security Vulnerability Submission Form, or
- Send email to: NVIDIA PSIRT
If reporting a potential vulnerability via email, please encrypt it using NVIDIA’s public PGP key (see PGP Key page) and include the following information:
- Product/Driver name and version/branch that contains the vulnerability
- Type of vulnerability (code execution, denial of service, buffer overflow, etc.)
- Instructions to reproduce the vulnerability
- Proof-of-concept or exploit code
- Potential impact of the vulnerability, including how an attacker could exploit the vulnerability
You may also use GitHub’s private vulnerability reporting on this repository (Security tab → Report a vulnerability) as an additional channel; PSIRT remains the fastest path to triage and tracking.
Refer to NVIDIA Security for past NVIDIA Security Bulletins and Notices.