Nvidia patches high-severity CVE-2026-47483 in DCGM Exporter after 2,000+ exposed instances found leaking GPU infrastructure details
Nvidia fixed CVE-2026-47483 (CVSS 8.2), allowing unauthenticated attackers to crash GPU monitoring via memory exhaustion; researchers found 2,000+ internet-exposed DCGM Exporter instances covering 12,000+ GPUs across ~300 organizations.
Lava Security researchers found more than 2,000 servers exposing NVIDIA's DCGM Exporter over unauthenticated plaintext HTTP between March and May, spanning roughly 300 organizations and covering over 12,000 unique GPU UUIDs on Blackwell Ultra B300, H200, H100, RTX 5090, and RTX 4090 systems — hardware CSO Online estimated at roughly $100 million. The US hosted 44% of exposed GPUs (5,274), followed by Romania and China, with exposed instances at customers of Voltage Park, Lambda, Northern Data, Nebius, and DigitalOcean, all of whom reportedly worked with customers after notification. The exposed telemetry revealed GPU models, UUIDs, and utilization data useful for reconnaissance. Nvidia assigned CVE-2026-47483 (CVSS 8.2) for a flaw in which unauthenticated concurrent requests to Go's /debug/pprof profiling endpoints can exhaust memory and crash the exporter, potentially disrupting AI workloads on the host. About 25% of exposed hosts also exposed the unauthenticated debug profiler. Separately, researchers found 12,096 public Prometheus Node Exporter instances leaking firmware, OS, kernel, BIOS, hostname, and network details. Nvidia's fix ships in DCGM Exporter 4.8.2 or later; researchers also recommend disabling --enable-pprof and keeping exporters off the public internet.
- CVE-2026-47483, CVSS 8.2, fixed in DCGM Exporter 4.8.2 or later.
- Unauthenticated concurrent requests to /debug/pprof profiling endpoints can exhaust memory and crash the exporter, potentially disrupting AI training/inference on the host.
- Lava scans (March–May) found about 2,100 internet-exposed DCGM hosts covering roughly 12,000 GPU UUIDs at about 300 organizations, including Blackwell Ultra B300, H200, H100, RTX 5090, and RTX 4090 systems.
- Roughly 25% of exposed hosts also exposed Go's unauthenticated /debug/pprof debug profiler.
- The US hosted 44% of exposed GPUs (5,274), followed by Romania and China; Voltage Park, Lambda, Northern Data, Nebius, and DigitalOcean worked with customers after notification.
- CSO Online estimated the exposed GPU hardware at roughly $100 million.
- Separately, 12,096 public Prometheus Node Exporter instances leaked firmware, OS, kernel, BIOS, hostname, and network details.
- Mitigations: upgrade to DCGM Exporter 4.8.2+, disable --enable-pprof, and restrict exporter network access.
Coverage timelineoldest first · each row is one article
- · 2d agoHigh-severity Nvidia bug could crash GPU monitoring on exposed servers
The Register · Security· 68
Nvidia patched CVE-2026-47483, a high-severity flaw that can crash exposed DCGM Exporter GPU monitoring.
- · 1d agoHigh-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring
Help Net Security· 55
Lava found 2,000+ internet-exposed NVIDIA DCGM Exporters covering 12,000+ GPUs across ~300 organizations, vulnerable to CVE-2026-47483 resource-exhaustion crashes.
- · 1d ago
Vulnerabilities in this storyAll →
- CVE-2026-474838.2<1%NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-47483 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption… NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure. |