Severity
High
Analysis Summary
CVE-2025-33214 CVSS:8.8
NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
CVE-2025-33213 CVSS:8.8
NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Impact
- Denial of Service
- Code Execution
- Information Disclosure
Indicators of Compromise
CVE
CVE-2025-33214
CVE-2025-33213
Affected Vendors
- NVIDIA
Affected Products
- NVIDIA Merlin Transformers4Rec
- NVIDIA NVTabular
Remediation
Refer to NVIDIA Security Advisory for patch, upgrade, or suggested workaround information.

