helpnetsecurity.com web signal

NVIDIA DCGM Exporter CVE-2026-47483 Lets Unauthenticated Attackers Crash GPU Monitoring on 2,000+ Exposed Servers

Summary

Lava Security's Michael Katchinskiy disclosed CVE-2026-47483 (CVSS 8.2) in NVIDIA's DCGM Exporter, letting unauthenticated attackers crash GPU monitoring via exposed debug endpoints and resource exhaustion. The researcher found more than 2,000 internet-exposed DCGM Exporter instances, representing roughly $100M in NVIDIA hardware across nearly 300 organizations. Fixed in DCGM Exporter 4.8.2; the `--enable-pprof` profiling endpoint is now opt-in by default.