
How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability

How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability

We discovered a high-severity vulnerability in NVIDIA’s GPU monitoring software that lets attackers remotely crash monitoring and exhaust server resources without authentication. We found 2,100+ exposed servers monitoring 12,000+ GPUs. Full research: https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability

Lava found about 2,100 GPU servers leaking Nvidia DCGM Exporter metrics with no authentication, The Register reports. The hosts span about 300 organizations and about $100 million in GPU hardware. Nvidia fixed it in version 4.8.2 (CVE-2026-47483, CVSS 8.2).

🚨 Falla grave en herramienta de monitoreo de GPU de Nvidia Lava detectó unos 2.100 servidores expuestos sin autenticación y 12.000 UUID visibles. La CVE-2026-47483 podía agotar la memoria y afectar la monitorización y cargas de IA. La corrección está en DCGM Exporter 4.8.2 o posterior.

🚨 exposed CVE-2026-47483 in NVIDIA GPU exporters. Patch now. #ThreatIntel #CVE #InfoSec" https://pranithjain.qzz.io/threatintel/cyberpulse