Science & Tech · Cybersecurity · 2 days ago
Thousands of GPU servers exposed monitoring data, with hundreds vulnerable to crashes
Researchers found about 2,100 GPU servers exposing Nvidia’s DCGM Exporter monitoring service to the internet.
The servers belonged to nearly 300 organizations, and the exposed data included details about more than 12,000 GPUs.
Some endpoints also exposed a profiling tool that could be overwhelmed by unauthenticated requests, crashing the monitoring service and potentially affecting AI training or inference.
The flaw is tracked as CVE-2026-47483 and was rated high severity by Nvidia.
Nvidia released a fix in version 4.8.2, and operators are advised to upgrade to that version or later.
Researchers also found 12,096 public Node Exporter hosts revealing server and operating-system details that could help attackers map systems.
The exposed services appeared on infrastructure used by several cloud providers, whose teams worked with customers to address exposures.
Monitoring services should be restricted to authorized systems rather than made directly reachable from the public internet.
Researchers found about 2,100 GPU servers exposing NVIDIA’s DCGM Exporter monitoring metrics to the internet without authentication.
Hundreds of the exposed services could be crashed by unauthenticated requests, potentially disrupting AI workloads.
The flaw is tracked as CVE-2026-47483, and NVIDIA fixed it in DCGM Exporter version 4.8.2.
The exposed servers belonged to nearly 300 organizations and reported more than 12,000 GPU identifiers.
Researchers also found 12,096 public Node Exporter hosts exposing server and operating-system details.
- Who
- Researchers at Lava found the exposed services. NVIDIA makes DCGM Exporter.
- What
- Unauthenticated attackers could crash the monitoring service by sending enough concurrent requests. This could affect AI training or inference workloads.
- When
- Researchers scanned between March and May 2026. NVIDIA’s fix timing is reported differently: July 28 in Help Net Security and September in The Register.
- Where
- On internet-exposed GPU servers belonging to nearly 300 organizations.
- Why
- Some exposed profiling endpoints allowed enough concurrent requests to exhaust memory and crash the exporter.
This story does not have two clearly opposing sides.
With enough concurrent unauthenticated requests, the exporter could run out of memory and crash, cutting off visibility into GPU health and activity
Those exposures can reveal how AI environments are built and, in some cases, allow attackers to disrupt them.
Every host returned metrics over plaintext HTTP, and none required authentication.
Lava conducted four scans and found about 2,100 GPU servers exposing DCGM Exporter metrics.
Help Net Security says NVIDIA published a security bulletin for the flaw.
The Register says NVIDIA released a fix for the flaw.
- Vulnerability
- CVE-2026-47483
- Affected service
- NVIDIA DCGM Exporter
- Fix
- Version 4.8.2
- Exposed GPU servers
- About 2,100
- Organizations
- Nearly 300
- Public Node Exporter hosts
- 12,096











