Vulnerability
Published 2026-10-08
Verified 2026-10-09

NVIDIA DCGM Exporter CVE-2026-47483 (CVSS 8.2): unauthenticated profiling endpoints can crash GPU monitoring; LAVA found 2,100+ exporters open to the internet leaking telemetry from 12,000+ GPUs; fixed in 4.8.2

LAVA published research on 8 October 2026 about CVE-2026-47483, a flaw it reported in NVIDIA's DCGM Exporter, the tool that publishes GPU health and usage metrics (typically on port 9400) for systems such as Prometheus. The exporter exposed Go's /debug/pprof profiling endpoints without authentication, and enough concurrent profiling requests can exhaust memory and crash it, blinding operators to GPU health and possibly slowing training or inference on the same host (CWE-770; NVIDIA rates it 8.2, denial of service and information disclosure). LAVA reproduced the behaviour with NVIDIA's official container unmodified. In four internet scans it found more than 2,000 hosts exposing the exporter without authentication, reporting over 12,000 unique GPUs including Blackwell Ultra B300, H200 and H100 parts as well as RTX 5090 and 4090 cards; many sat on customer infrastructure at GPU cloud providers such as Voltage Park, Lambda, Northern Data and DigitalOcean, which helped notify customers. LAVA did not test the crash against public systems. NVIDIA's July 2026 bulletin fixed the issue in the release pairing DCGM 4.5.3 with DCGM Exporter 4.8.2, which makes pprof opt-in (--enable-pprof or DCGM_EXPORTER_ENABLE_PPROF). No exploitation has been reported. Primary: NVIDIA bulletin and LAVA; wire: SecurityWeek.

Product
NVIDIA DCGM Exporter (GPU telemetry exporter) — /debug/pprof endpoints
Versions
DCGM Exporter up to 4.8.2 and DCGM up to 4.5.2 per the CVE record; NVIDIA lists the 4.5.3-4.8.2 release as the fix
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade to the DCGM 4.5.3 / DCGM Exporter 4.8.2 release or later and leave pprof disabled. Bind the exporter to a private interface or put it behind authentication, and check that port 9400 on GPU hosts is not reachable from the internet.

Primary: LAVA — CVE-2026-47483: NVIDIA DCGM Exporter vulnerability exposes GPU servers (8 Oct 2026) · Vendor: NVIDIA — Security Bulletin: NVIDIA DCGM Exporter, July 2026 (CVE-2026-47483) · CVE: CVE-2026-47483 · SecurityWeek — In Other News: exposed Nvidia DCGM exporters leak telemetry from 12,000 GPUs (9 Oct 2026)

tech ai cloud