Nvidia Patches High-Severity Flaw in GPU Monitoring Tool After Thousands of Servers Found Exposed
Nvidia recently addressed a high-severity vulnerability (CVE-2026-47483, CVSS 8.2) in its DCGM Exporter, a tool that monitors GPU health and performance metrics including hardware telemetry, utilization, memory usage, and power consumption. The flaw, discovered by researcher Michael Katchinskiy of cybersecurity startup Lava, could allow unauthenticated attackers to crash the monitoring service, disrupting AI workloads by exhausting system memory through excessive requests.
Between March and May 2024, Lava’s scans revealed 2,100 GPU servers exposing DCGM Exporter metrics to the internet without authentication, encompassing 12,000 GPUs across 300 organizations. Nearly 44% of the exposed GPUs (5,274 units) were located in the U.S., with hardware valued at approximately $100 million. Affected systems included high-end AI accelerators like Nvidia’s Blackwell Ultra B300, H200, and H100 GPUs, as well as consumer-grade RTX 5090 and 4090 models.
Beyond GPU telemetry, 25% of the exposed hosts also leaked sensitive runtime data via Go’s /debug/pprof/ profiler, exposing CPU/memory usage, goroutine states, and other performance details. This information could aid attackers in reconnaissance, mapping infrastructure, or identifying vulnerable configurations.
Nvidia released a fix in DCGM Exporter version 4.8.2, urging operators to upgrade. Separately, Lava identified 12,096 publicly exposed Prometheus Node Exporter instances, which disclosed server models, OS versions, hostnames, and networking hardware further aiding potential attackers in targeting GPU clusters.
The exposed infrastructure spanned multiple cloud providers, including Nebius, Voltage Park, Lambda, Northern Data, and DigitalOcean. While Lava reported the findings to affected vendors, the incident underscores a broader security risk: AI infrastructure worth millions remains exposed due to misconfigured monitoring tools, leaving critical systems vulnerable to disruption or exploitation.
Nvidia TPRM report: https://www.rankiteo.com/company/nvidia
Lambda TPRM report: https://www.rankiteo.com/company/lambda-labs
Northern Data TPRM report: https://www.rankiteo.com/company/northerndatagroup
"id": "lamnvinor1791491254",
"linkid": "lambda-labs, nvidia, northerndatagroup",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '300 organizations',
'industry': 'Semiconductors, AI, GPU Manufacturing',
'location': 'Global (HQ: Santa Clara, California, USA)',
'name': 'Nvidia',
'size': 'Large Enterprise',
'type': 'Technology Company'},
{'industry': 'Cloud Computing',
'name': 'Nebius',
'type': 'Cloud Provider'},
{'industry': 'Cloud Computing',
'name': 'Voltage Park',
'type': 'Cloud Provider'},
{'industry': 'Cloud Computing',
'name': 'Lambda',
'type': 'Cloud Provider'},
{'industry': 'Cloud Computing, AI Infrastructure',
'name': 'Northern Data',
'type': 'Cloud Provider'},
{'industry': 'Cloud Computing',
'name': 'DigitalOcean',
'size': 'Large Enterprise',
'type': 'Cloud Provider'}],
'attack_vector': 'Unauthenticated Remote Exploitation',
'data_breach': {'personally_identifiable_information': 'No',
'sensitivity_of_data': 'High (infrastructure mapping, '
'performance metrics)',
'type_of_data_compromised': 'GPU telemetry, runtime '
'performance data, server '
'configurations'},
'date_detected': '2024-03-01',
'description': 'Nvidia addressed a high-severity vulnerability '
'(CVE-2026-47483, CVSS 8.2) in its DCGM Exporter tool, which '
'monitors GPU health and performance metrics. The flaw could '
'allow unauthenticated attackers to crash the monitoring '
'service by exhausting system memory through excessive '
'requests. Between March and May 2024, 2,100 GPU servers '
'exposing DCGM Exporter metrics without authentication were '
'discovered, encompassing 12,000 GPUs across 300 '
'organizations. Nearly 44% of the exposed GPUs were in the '
'U.S., with hardware valued at approximately $100 million. '
'Additionally, 25% of the exposed hosts leaked sensitive '
'runtime data via Go’s /debug/pprof/ profiler, aiding '
'potential attackers in reconnaissance.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'exposed infrastructure',
'data_compromised': 'GPU telemetry, CPU/memory usage, goroutine '
'states, server models, OS versions, '
'hostnames, networking hardware',
'downtime': 'Potential disruption of AI workloads',
'operational_impact': 'Disruption of GPU monitoring services, '
'potential AI workload interruptions',
'systems_affected': '2,100 GPU servers (12,000 GPUs)'},
'investigation_status': 'Ongoing (as of disclosure)',
'lessons_learned': 'Misconfigured monitoring tools can expose critical AI '
'infrastructure to disruption or exploitation. '
'Organizations must ensure proper authentication and '
'access controls for monitoring services.',
'post_incident_analysis': {'corrective_actions': 'Patch management, access '
'control enforcement, '
'disabling debug endpoints',
'root_causes': 'Misconfigured DCGM Exporter '
'instances exposed to the internet '
'without authentication, enabling '
'unauthenticated access to '
'sensitive monitoring data'},
'recommendations': ['Upgrade to DCGM Exporter version 4.8.2 or later',
'Restrict access to monitoring tools to authenticated '
'users only',
'Disable unnecessary debug endpoints like /debug/pprof/',
'Conduct regular security audits of exposed '
'infrastructure',
'Implement network segmentation for GPU clusters'],
'references': [{'source': 'Lava (cybersecurity startup)'},
{'source': 'Nvidia Security Advisory'}],
'response': {'containment_measures': 'Nvidia released a fix in DCGM Exporter '
'version 4.8.2',
'remediation_measures': 'Upgrade to DCGM Exporter version 4.8.2',
'third_party_assistance': 'Lava (cybersecurity startup)'},
'title': 'Nvidia Patches High-Severity Flaw in GPU Monitoring Tool After '
'Thousands of Servers Found Exposed',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-47483'}