Unauthenticated Attackers Can Crash NVIDIA DCGM Exporter (CVE-2026-47483), Threatening AI GPU Monitoring
A high‑severity flaw (CVE‑2026‑47483) in NVIDIA’s DCGM Exporter lets anyone on the Internet send crafted requests that crash the metrics service, exposing GPU inventory and potentially halting AI workloads. The issue underscores the importance of authenticated observability controls for audit‑ready environments.
ADTP Breach Watch· October 9, 2026· Help Net Security
Researchers from Lava discovered that more than 2,000 internet‑exposed GPU servers were running NVIDIA’s DCGM Exporter without authentication. By flooding the `/metrics` or `/debug/pprof` endpoints, an attacker can exhaust memory and crash the exporter, denying visibility into GPU health and utilization.
Why it matters for trust and compliance
The flaw demonstrates a gap in the control objective that only authorized entities may access system monitoring data, a requirement across frameworks such as NIST CSF. Remediating it restores a defensible audit trail and supports continuous control assurance.
Enforcing authentication on monitoring endpoints provides concrete evidence of access‑control compliance.
Continuous health‑check monitoring of exporter availability creates an auditable log of service integrity.
Who is affected
CLOUD_INFRATECH_SAAS
Recommended actions
Inventory all DCGM Exporter deployments and block public Internet access.
Apply NVIDIA’s July 2026 patch to every exporter instance.
Implement strong authentication (e.g., mTLS or API tokens) for `/metrics` and `/debug/pprof` endpoints.
Add firewall/allow‑list rules limiting access to trusted Prometheus collectors.
Integrate exporter uptime checks into your continuous control‑monitoring platform.
Details
CVEs
CVE-2026-47483
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.