Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

CVE-2026-47483: NVIDIA DCGM Exporter Flaw Left More Than 12,000 GPUs Exposed, Researchers Say

Дата публикации: 09-10-2026 11:24:03

A high-severity vulnerability in NVIDIA DCGM Exporter, a widely used tool for monitoring GPUs across AI servers and clusters, could let unauthenticated attackers disrupt monitoring and potentially AI workloads without authentication, leading to denial of service (DOS) and information disclosure.  Tracked as CVE-2026-47483 (CVSS 8.2), the vulnerability was detailed by Lava Security, which mentioned uncovering […]

Основное содержимое страницы с новостью.

NVIDIA - GPU Monitoring Software - Hardware

Key Takeaways

  • CVE and Severity: NVIDIA assigned CVE-2026-47483 a CVSS score of 8.2 (High) for a flaw in NVIDIA DCGM Exporter.

  • Massive Internet Exposure: More than 2,000 servers exposed the exporter, reporting over 12,000 GPUs worth an estimated $100 million.

  • Patch Available: Operators should upgrade DCGM Exporter to version 4.8.2 or later.

A high-severity vulnerability in NVIDIA DCGM Exporter, a widely used tool for monitoring GPUs across AI servers and clusters, could let unauthenticated attackers disrupt monitoring and potentially AI workloads without authentication, leading to denial of service (DOS) and information disclosure. 

Tracked as CVE-2026-47483 (CVSS 8.2), the vulnerability was detailed by Lava Security, which mentioned uncovering 2,100 servers leaking telemetry from 12,096 GPUs to anyone online.

How /debug/pprof Exhaustion Can Crash the Exporter

About a quarter of exposed DCGM Exporter hosts served Go’s /debug/pprof/ profiling endpoints alongside /metrics, the report said. With enough concurrent unauthenticated requests, researchers estimate the exporter could run out of memory and crash, cutting off visibility into GPU health and activity. 

Exposed GPUs by sector | Source: Lava

The resulting CPU and RAM pressure could also slow training or inference workloads on the same host. Lava reproduced the behavior using NVIDIA’s official, unmodified DCGM Exporter container and tested the resource exhaustion only in a controlled environment.

“We found 12,096 public Node Exporter hosts reporting mlx5 metrics from NVIDIA/Mellanox InfiniBand and RoCE adapters, exposing adapter models, firmware versions, link state and fabric activity,” researchers said. “Many also revealed hostnames, OS and kernel versions, and BIOS details.”

Exposed NVIDIA H100, H200, B200, and B300 GPUs

Lava ran four scans between March and May 2026. Every exposed host returned metrics over plaintext HTTP, and none required authentication. “Current-generation Blackwell hardware was wide open, including 312 NVIDIA B200s, and 32 B300s, with their telemetry accessible without authentication.”

“Anyone who could reach these endpoints could see what hardware organizations were running, how heavily it was being used, and details about the AI infrastructure around it,” the report said. 

US, Romania, and China Lead GPU Exposure

Endpoints in the United States accounted for 5,274 GPUs (44%). Romania followed with 2,054 (17%), and China had 1,967 (16%).

Voltage Park, Lambda, Northern Data, and DigitalOcean Infrastructure Involved

Many exposed services ran on customer infrastructure associated with neoclouds, also known as GPU cloud providers, including:

  • Voltage Park, 
  • Lambda, 
  • Northern Data, 
  • DigitalOcean.

The largest documented group was associated with Voltage Park: 672 public node_exporter hosts and 71 public DCGM Exporter hosts. Voltage Park confirmed that most of the node_exporter instances and all the DCGM Exporter instances were customer-deployed.

NVIDIA Security Bulletin and Steps to Reduce Risk

NVIDIA published a security bulletin on CVE-2026-47483 in July 2026. Besides upgrading to version 4.8.2 or later, operators should take these steps:

  • Keep --enable-pprof disabled unless profiling is explicitly required.
  • Bind exporters to loopback or private interfaces.
  • Restrict access with firewall rules or security groups.

A 2024 report from Aqua Security said that over 300,000 Prometheus servers and exporters were exposed to DoS attacks. 

In June, reports said OpenAI Codex uncovered an HTTP/2 bomb DoS exploit affecting nginx, Apache, and Microsoft IIS.

Explore More

Most Popular

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours013.5924-09-2026
2CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally07.6328-09-2026
3Atlassian Data Center Flaw Sparks Attacks in Hours as Enterprises Race to Patch Eight Products09.1407-10-2026
4Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution08.3930-09-2026
5Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT07.930-09-2026
6[0day-rubbish] IPConfigure Orchid VMS 26.3.0 authenticated DNF repository GPG-key property command injection to root (7.2)09.0406-10-2026
7Another Dozen Vulnerabilities Found In The X.Org Server & XWayland05.2907-10-2026
8Nvidia’s Answer to Rogue Agents Is an Open-Source AI Security System012.228-09-2026
9SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-463807.7806-10-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 11.94. Источник: www.technadu.com.