Nvidia has released a fix for a high-severity vulnerability in its DCGM Exporter, a service that collects GPU telemetry such as utilization, memory usage, and power consumption. The flaw, tracked as CVE-2026-47483 and rated 8.2 on the CVSS scale, could let an unauthenticated attacker crash the monitoring service by sending enough concurrent requests. That could cut off visibility into GPU health and put pressure on AI training or inference workloads running on the same host.

The bug was reported by Lava, a datacenter security startup, and Nvidia patched it in version 4.8.2. Lava researchers then scanned the internet and found about 2,100 GPU servers exposing DCGM Exporter metrics without authentication, representing 12,000 GPU UUIDs across roughly 300 organizations. Nearly half of the exposed GPUs were in the US, and the hardware included Nvidia Blackwell Ultra B300, H200, H100, and RTX 5090 and 4090 systems, worth an estimated $100 million. The researchers also found about 12,000 public Node Exporter hosts exposing server and networking details, and noted that 25 percent of the exposed DCGM hosts leaked Go runtime profiling data via /debug/pprof/.