affected: - ecosystem_specific: {} package: ecosystem: PyPI name: nemo-asr purl: pkg:pypi/nemo-asr ranges: - events: - introduced: '0' - last_affected: 1.22.0 type: ECOSYSTEM versions: - '0.8' - 0.8.1 - 0.8.2 - 0.9.0 aliases: - CVE-2024-0081 - GHSA-x392-p65g-4rxx details: |2+ NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits or throttling. A successful exploit of this vulnerability may lead to a server-side denial of service. id: PYSEC-2024-289 modified: '2026-05-21T14:54:35.832106Z' published: '2024-04-05T19:15:07.033Z' references: - type: ADVISORY url: https://github.com/NVIDIA/NeMo/security/advisories/GHSA-x392-p65g-4rxx severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H type: CVSS_V3