Saturday, October 10, 2026Publish a press release →
Submit a Release
Security

Nvidia DCGM Exporter Flaw Could Let Attackers Crash GPU Monitoring on Exposed Servers

CVE-2026-47483 is rated 8.2; researchers found more than 12,000 GPUs sitting behind internet-exposed exporters.

Nvidia DCGM Exporter Flaw Could Let Attackers Crash GPU Monitoring on Exposed Servers

Photo: Will Buckner / CC BY 2.0 via Wikimedia Commons

A high-severity vulnerability in Nvidia's DCGM Exporter, a tool that publishes GPU telemetry for monitoring systems, could allow an unauthenticated attacker to crash the exporter on servers reachable from the internet, according to Help Net Security. The flaw is tracked as CVE-2026-47483 and was rated 8.2 by Nvidia.

The vulnerability

The issue sits in the exporter's Go profiling endpoints under `/debug/pprof/`. Nvidia published its security bulletin on July 28, 2026, and credited researcher Michael Katchinskiy of Lava with reporting it. The fix is in DCGM Exporter 4.8.2 or later. The article does not state which earlier versions are affected.

Nvidia also advises leaving the `--enable-pprof` flag off unless profiling is needed.

How many systems are exposed

Lava's research, based on four internet scans from March to May 2026, found:

  • More than 2,000 exposed DCGM Exporter instances
  • More than 12,000 unique GPUs behind them, which Help Net Security reports as an estimated $100 million in hardware
  • Nearly 300 organizations affected
  • The United States hosting 5,274 exposed GPUs (44%), followed by Romania with 2,054 and China with 1,967

"Every host returned metrics over plaintext HTTP, and none required authentication," Katchinskiy wrote.

Why it matters

A crash would disable monitoring rather than the GPUs themselves, but telemetry is how operators track utilization, temperature and faults across AI clusters. The exposure also shows that the exporters were reachable without access controls, a configuration problem that updating the software alone does not address.

Operators running DCGM Exporter should upgrade to the fixed release and restrict network access to the metrics endpoint, as described in Nvidia's bulletin.

More Nvidia news →

Related Coverage