Exposed Nvidia GPU monitors can reveal AI infrastructure secrets
NVIDIA patched high-severity CVE-2026-47483 in DCGM Exporter; 2,000+ internet-exposed instances covering 12,000+ GPUs allowed unauthenticated DoS and reconnaissance.
Lava Security found over 2,000 GPU servers exposing NVIDIA DCGM Exporter without authentication, reporting more than 12,000 unique GPUs worth an estimated $100 million. Unauthenticated concurrent requests to /debug/pprof/ profiling endpoints can exhaust memory and crash the exporter, potentially disrupting AI training/inference on the same host. NVIDIA assigned CVE-2026-47483 (CVSS 8.2) and fixed it in DCGM Exporter 4.8.2; about a quarter of exposed instances served the vulnerable profiling endpoints.