ComputersAI

Nvidia Patches High-Severity DCGM Exporter Flaw

Nvidia released DCGM Exporter 4.8.2 to fix CVE-2026-47483, an 8.2-severity denial-of-service bug found by Lava researchers.

Nvidia has released DCGM Exporter version 4.8.2 to address a high-severity vulnerability tracked as CVE-2026-47483, according to howtogeek.com. The company is advising administrators to upgrade to that version or later.

The flaw carries a CVSS score of 8.2. Researchers at the security firm Lava discovered it and found that an unauthenticated attacker could send requests to exposed pprof profiling endpoints to trigger a denial-of-service attack.

Exposed systems identified during the research included Nvidia Blackwell Ultra B300, H200, and H100 GPUs used for AI workloads, as well as consumer RTX 5090 and 4090 systems.

Earlier exposure findings

During four scans between March and May 2026, researchers found about 2,100 GPU servers exposing data publicly without login. Those systems revealed information about more than 12,000 individual GPUs, representing an estimated $100 million in hardware. Consumer GPUs and mining farms accounted for around 35% of the exposed systems, and the United States had the biggest share with 5,274 GPUs, about 44% of all GPUs identified.

Quick answers

What is CVE-2026-47483?

It is a high-severity vulnerability in Nvidia's DCGM Exporter with a CVSS score of 8.2. An unauthenticated attacker could send requests to exposed pprof profiling endpoints to trigger a denial-of-service attack.

How do I fix the Nvidia DCGM Exporter vulnerability?

Nvidia advises administrators to upgrade DCGM Exporter to version 4.8.2 or later.

Who discovered the DCGM Exporter flaw?

Researchers at the security firm Lava discovered the vulnerability.

Source