• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
Technology
Report

NVIDIA DCGM Exporter vulnerability found amid reports of 2,100+ servers exposing metrics from 12,000+ GPUs

NEXSIGHT, citing Lava Security, reports an unauthenticated denial-of-service flaw and lists version 4.8.2 as the fix.

Read the DiffRT
NEXSIGHTNE
2 Sources, 11h ago, first seen 11h ago

TLDR

NEXSIGHT, summarizing Lava Security's initial report, says about 2,100 servers exposed data on more than 12,000 GPUs and identifies version 4.8.2 as the fixed release. A separate post says DCGM Exporter exposes metrics without authentication by default and that concurrent requests to its profiling endpoints can exhaust the monitoring service. That post cautions that its early account is unconfirmed.

Combined views

69

2 Sources, first seen 11h ago

1 comments

Combined views

69

2 Sources, first seen 11h ago

1 comments

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Featured Source

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

2 Sources

Read the Diff@read__the__diff‼️ 2,100 GPU servers are broadcasting their telemetry to anyone, and one of them can be brought to its knees by **a single unauthenticated request**. NVIDIA DCGM Exporter is a small service that exposes a GPU server's metrics, meaning the numbers the machine publishes about its own operation: temperature, load, memory used. It runs alongside Prometheus, the tool that comes and reads those numbers to display them on a dashboard. The catch is that DCGM Exporter has no authentication by default: if you expose it on the internet, anyone can read those metrics. That is what http://lava.security researchers found on 2,100 servers, covering about 300 organizations and more than 12,000 GPUs, roughly $100 million in hardware according to Cybernews. The real subject is not the telemetry leak, which is already bad practice but remains indirect information. The real subject is CVE-2026-47483, the vulnerability those same researchers found in the /debug/pprof endpoints, the diagnostic entry points the service exposes so a developer can profile its performance. These endpoints accept concurrent profiling requests without authentication, and each request consumes resources. Send enough in parallel and the service exhausts itself and goes down. Monitoring stops, and the AI workloads that relied on it to drive their scheduling lose their feedback loop. Two problems overlap here. The first is a widespread configuration error, exposing an internal service to the public internet. The second is a design flaw, a diagnostic endpoint shipped without access control and without rate limiting. The second turns the first from negligence into an operational incident. A GPU server that loses its monitoring does not stop on its own, but the team watching it goes blind at the exact moment it would need to see. Audit your DCGM Exporter deployments to confirm they are not reachable from outside, put authentication or a firewall in front, and disable the /debug/pprof endpoints if they are not in use. To detect ongoing exploitation, watch for spikes in concurrent requests on those endpoints and unexplained service restarts. Early report: these facts come from first disclosures and are not confirmed yet. Expect them to change.11h
NEXSIGHT@NEXSIGHTNEWSNVIDIAのGPU監視ツール「DCGM Exporter」にDoSの脆弱性CVE-2026-47483 — Lavaが報告、世界2,100超のサーバーが1万2,000基のGPU情報を外部に露出 https://cyber.nexsight.co/articles/2026/10/11/nvidia-dcgm-exporter-cve-2026-47483-dos-exposure-2026-10-11/2h
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI

    2 Sources

    Read the Diff@read__the__diff‼️ 2,100 GPU servers are broadcasting their telemetry to anyone, and one of them can be brought to its knees by **a single unauthenticated request**. NVIDIA DCGM Exporter is a small service that exposes a GPU server's metrics, meaning the numbers the machine publishes about its own operation: temperature, load, memory used. It runs alongside Prometheus, the tool that comes and reads those numbers to display them on a dashboard. The catch is that DCGM Exporter has no authentication by default: if you expose it on the internet, anyone can read those metrics. That is what http://lava.security researchers found on 2,100 servers, covering about 300 organizations and more than 12,000 GPUs, roughly $100 million in hardware according to Cybernews. The real subject is not the telemetry leak, which is already bad practice but remains indirect information. The real subject is CVE-2026-47483, the vulnerability those same researchers found in the /debug/pprof endpoints, the diagnostic entry points the service exposes so a developer can profile its performance. These endpoints accept concurrent profiling requests without authentication, and each request consumes resources. Send enough in parallel and the service exhausts itself and goes down. Monitoring stops, and the AI workloads that relied on it to drive their scheduling lose their feedback loop. Two problems overlap here. The first is a widespread configuration error, exposing an internal service to the public internet. The second is a design flaw, a diagnostic endpoint shipped without access control and without rate limiting. The second turns the first from negligence into an operational incident. A GPU server that loses its monitoring does not stop on its own, but the team watching it goes blind at the exact moment it would need to see. Audit your DCGM Exporter deployments to confirm they are not reachable from outside, put authentication or a firewall in front, and disable the /debug/pprof endpoints if they are not in use. To detect ongoing exploitation, watch for spikes in concurrent requests on those endpoints and unexplained service restarts. Early report: these facts come from first disclosures and are not confirmed yet. Expect them to change.11h
    NEXSIGHT@NEXSIGHTNEWSNVIDIAのGPU監視ツール「DCGM Exporter」にDoSの脆弱性CVE-2026-47483 — Lavaが報告、世界2,100超のサーバーが1万2,000基のGPU情報を外部に露出 https://cyber.nexsight.co/articles/2026/10/11/nvidia-dcgm-exporter-cve-2026-47483-dos-exposure-2026-10-11/2h
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet