// 2 ZERO-DAY · 3 CVE · 1 ADVISORY IN THE LAST 24H→
CVE-2026-47483 hits NVIDIA GPU monitoring: 2,100 internet-exposed servers, 12,000 GPUs vulnerable to DoS via /debug/pprof endpoint. The fix is in DCGM Exporter 4.8.2.

On July 28, 2026, NVIDIA published bulletin 5857. It did not escape the notice of security operators, but the scale of exposure only surfaced on October 6, when Lava Security researchers completed a systematic scan of DCGM Exporter endpoints across the internet. The result: roughly 2,100 servers exposing over 12,000 GPUs with zero authentication, representing an estimated $100 million in hardware value. The vulnerability, tracked as CVE-2026-47483 with a CVSS score of 8.2, does not target the GPUs themselves, but the monitoring service that administers them.

Key Takeaways
  • CVE-2026-47483 is a high-severity vulnerability in NVIDIA DCGM Exporter with CVSS 8.2, published in NVIDIA bulletin 5857 on July 28, 2026
  • The attack requires only unauthenticated concurrent requests to /debug/pprof endpoints to exhaust memory and stop the monitoring service
  • A Lava Security scan identified roughly 2,100 GPU servers exposed on the internet, exposing over 12,000 GPU UUIDs without authentication
  • NVIDIA released the fix in DCGM Exporter version 4.8.2; affected versions range from 0.0 to 4.8.2

The Mechanism: How a Profiling Endpoint Becomes a Weapon

The DCGM Exporter is the standard tool NVIDIA distributes to expose GPU metrics in Kubernetes and Prometheus environments. It typically runs on port 9400, serving HTTP endpoints such as /metrics for Prometheus metrics and, more problematically, /debug/pprof for runtime profiling of the underlying Go application.

According to the CVE-2026-47483 record in the National Vulnerability Database, the attack vector is network (AV:N), complexity is low (AC:L), privileges required are none (PR:N), and user interaction is none (UI:N). Availability impact is high (A:H), with low confidentiality impact (C:L) and no integrity impact (I:N). The full CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H.

The mechanism is straightforward but effective: an attacker sends unauthenticated concurrent requests to the Go profiling endpoints. The service, forced to generate heap, CPU, and goroutine profiles in parallel, consumes memory until exhaustion. The process crashes. Visibility into GPU state disappears, and CPU and RAM pressure on the host can spill over to AI workloads running on the same node.

The Scale: 2,100 Hosts, 12,000 GPUs, Zero Authentication

The numbers from Lava Security's research, conducted by Michael Katchinskiy, leave no room for optimistic interpretation. Roughly 2,100 GPU servers exposed DCGM Exporter on public internet interfaces. None required authentication. From the exposed services, researchers extracted over 12,000 GPU UUIDs—unique identifiers that tie each hardware unit to a specific tenant in the infrastructure.

The geographic breakdown shows a sharp concentration: roughly 44% of exposed GPUs, or 5,274 units, resided in the United States. The identified units range from high-end datacenter accelerators—H100, H200, Blackwell B300—to consumer cards like the RTX 4090 and 5090. Approximately 25% of exposed hosts also served the /debug/pprof/ endpoints, those directly exploitable for DoS.

The estimated value of exposed hardware reaches roughly $100 million. The identified GPUs belong to approximately 300 distinct organizations, a figure that suggests a systemic problem rather than an isolated incident involving a few careless operators.

The Risk Profile: What Gets Exposed Beyond DoS

The CVSS classification emphasizes DoS, but the exposure carries a significant informational payload. The DCGM Exporter's /metrics endpoints reveal granular data on GPU state: memory utilization, temperature, power consumption, running processes, Kubernetes container identifiers using them. Michael Katchinskiy, founder of Lava Security, framed the problem in an interview with The Register.

"Once we realized how much these endpoints revealed, the next question was: How many of them are exposed to the internet?" — Michael Katchinskiy, Lava Security

The quote, reported by The Register, frames the critical issue: the operational visibility that makes DCGM Exporter useful to administrators is identical to what makes it a privileged reconnaissance tool for an attacker. Knowing how many GPUs a node has, how they are allocated, which workloads are using them, and what the usage patterns look like is tactical intelligence for future attacks, not just for immediate DoS.

What to Do Now

Priority actions follow directly from the documented facts:

  • Verify exposure of DCGM Exporter endpoints on public interfaces, with particular attention to port 9400 and /debug/pprof endpoints
  • Upgrade to DCGM Exporter version 4.8.2, which, per NVIDIA bulletin 5857 and official release notes, fixes the vulnerability
  • Check running versions in your fleet: affected versions range from 0.0 to 4.8.2, including pre-patch 4.8.2 builds if identifiable by build or commit
  • Assess the need to expose the monitoring service on public interfaces, given that Lava Security's scan demonstrated roughly 300 organizations are doing so without authentication

The dossier does not specify whether NVIDIA has released indicators of compromise to identify potential prior exploitation, nor does it document the number of hosts that actually applied the patch in the July–October 2026 window.

The Gap Between Spending and Discipline: A Broader Read

CVE-2026-47483 is not a case of a sophisticated vulnerability evading extensive audits. It is a debugging endpoint left accessible on public interfaces, in a standard monitoring service distributed by NVIDIA itself. The vendor fixed the bug, but the fix has been available since July, and the October scan shows thousands of installations remain exposed.

The editorial angle suggested by the dossier is pertinent: investment in AI hardware is proceeding at a speed that finds no match in operational hardening processes. Organizations buy accelerators costing tens of thousands of dollars, deploy them in multi-tenant clusters, orchestrate them with Kubernetes—and leave the monitoring service exposed on the internet without a password. This is not a security budget problem, but a discontinuity between infrastructure acquisition and its securing.

The specific risk of CVE-2026-47483 is DoS. The systemic risk is confirmation that AI infrastructures, for all their cost and strategic value, are operated with the same basic gaps that have characterized traditional IT for decades. The difference is that here every exposed node is worth hundreds of thousands of dollars, and every workload interruption carries an opportunity cost measurable in lost training hours or violated inference contracts.

FAQ

Does the bug directly affect NVIDIA GPUs?
No. The vulnerability concerns the DCGM Exporter, the monitoring software service. The GPUs themselves, drivers, and firmware are not involved. The impact on GPUs is indirect: the monitoring crash can disrupt operational visibility and, under extreme pressure on shared resources, affect running workloads.
Why is the CVSS score 8.2 if the impact is "only" DoS?
CVSS 3.1 rewards ease of exploitation: network, no privileges, no user interaction. The high score reflects the likelihood that an attacker can cause damage without technical barriers. Availability impact is rated "high," and there is a low confidentiality impact (C:L) for information exposed by the endpoints.
Is there evidence of active exploitation in the wild?
The dossier does not document exploitation in production environments. Lava Security's tests were conducted in a controlled environment. It is unknown whether the exposed endpoints were subjected to real attacks before the research publication.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. theregister.com
  2. strix.ai
  3. cyberstrike.io
  4. nvidia.com
  5. nvd.nist.gov
  6. nvidia.custhelp.com
  7. lava.security
  8. cwe.mitre.org