High-severity Nvidia bug could crash GPU monitoring on exposed servers
Nvidia patched CVE-2026-47483, a high-severity flaw that can crash exposed DCGM Exporter GPU monitoring.
Nvidia fixed CVE-2026-47483, a CVSS 8.2 flaw in DCGM Exporter that lets unauthenticated attackers crash GPU monitoring by exhausting memory with concurrent requests, potentially disrupting AI workload visibility. Lava's scans between March and May found about 2,100 internet-exposed DCGM hosts, covering roughly 12,000 GPU UUIDs at about 300 organizations, including Blackwell Ultra B300, H200, H100, and RTX 5090 and 4090 systems. About 25 percent of those hosts also exposed Go's /debug/pprof profiler. Researchers separately found 12,096 public Prometheus Node Exporter instances and said Nebius, Voltage Park, Lambda, Northern Data, and DigitalOcean worked with customers after notification. Nvidia's fix is in version 4.8.2 or later.