NVIDIA has released an update for DCGM Exporter, the tool that publishes GPU telemetry over HTTP for monitoring systems such as Prometheus, to address CVE-2026-47483. NVIDIA’s security bulletin rates the flaw 8.2 (High) on CVSS v3.1. It describes uncontrolled resource consumption in the /debug/pprof endpoints, where an attacker could submit concurrent unauthenticated profiling requests. NVIDIA lists denial of service and information disclosure as the impacts, and tells users to update from the NVIDIA/dcgm-exporter GitHub repository.

The security firm Lava, which reported the flaw to NVIDIA, published research on how widely these exporters sit on the open internet. Across four scans between March and May 2026, Lava found roughly 2,100 hosts serving DCGM Exporter metrics publicly, reporting more than 12,000 unique GPUs. Lava says every host returned metrics over plaintext HTTP and none required authentication. About a quarter of the hosts also served Go’s pprof profiling endpoints alongside the metrics. Lava adds that the exposed services were mostly deployed and exposed by customers themselves, according to the GPU cloud providers it contacted.

The metrics alone show defenders what an outsider can learn. Lava notes that a single response identifies the exact GPU model, utilization, memory use and error events for each device, which can reveal how heavily a server is used and, where Kubernetes labels are present, the names of the projects running on it.

In our reading, the monitoring port is the part of the AI stack most likely to be treated as internal plumbing, so it is the part least likely to sit behind a firewall rule. The update fixes the CVE. The exposure Lava measured came from where the exporter was reachable, which a patch does not change.

What to do: update DCGM Exporter as NVIDIA’s bulletin directs, confirm the metrics port is not reachable from the internet, and put authentication or network policy in front of it. For related reading on exposed AI infrastructure, see our report on PoeLLM targeting exposed AI servers and why an exposure inventory decides the first hour after an advisory.

Source: NVIDIA, DCGM Exporter security bulletin, July 2026

Source: Lava, CVE-2026-47483 research on exposed DCGM Exporter hosts, October 2026