Full Report
The GPU giant released a fix for the flaw, tracked as CVE-2026-47483
Analysis Summary
# Vulnerability: Denial of Service in NVIDIA DCGM Exporter
## CVE Details
- **CVE ID:** CVE-2026-47483
- **CVSS Score:** 8.2 (High)
- **CWE:** CWE-400 (Uncontrolled Resource Consumption / Resource Exhaustion)
## Affected Systems
- **Products:** NVIDIA Data Center GPU Manager (DCGM) Exporter
- **Versions:** All versions prior to v4.8.2
- **Configurations:** Systems where the DCGM Exporter service is exposed to the internet or untrusted networks without authentication. This commonly affects GPU clusters in "neocloud" and GPU cloud environments (e.g., Lambda, DigitalOcean, Northern Data).
## Vulnerability Description
The NVIDIA DCGM Exporter, which collects GPU telemetry (utilization, memory, power) and exposes it via HTTP for Prometheus monitoring, is susceptible to a resource exhaustion flaw. Because the service lacks default authentication, an attacker can send a high volume of concurrent HTTP requests. This leads to excessive CPU and memory pressure, eventually causing the exporter to crash. Furthermore, the exposure often includes Go’s `/debug/pprof/` runtime profiling data, providing attackers with detailed insights into memory allocations and goroutine states to better tailor the exhaustion attack.
## Exploitation
- **Status:** Not exploited in the wild (reported by Lava security researchers); PoC demonstrated by researchers.
- **Complexity:** Low
- **Attack Vector:** Network (Unauthenticated HTTP requests)
## Impact
- **Confidentiality:** Low (Information disclosure of GPU UUIDs, hardware configurations, and performance metrics).
- **Integrity:** None
- **Availability:** High (Crash of monitoring services and potential performance degradation of AI training/inference workloads due to host CPU/RAM pressure).
## Remediation
### Patches
- **NVIDIA DCGM Exporter v4.8.2:** Operators should upgrade to version 4.8.2 or later immediately to resolve the resource management flaw.
### Workarounds
- **Network Segmentation:** Ensure DCGM Exporter, Node Exporter, and Prometheus services are not reachable from the public internet.
- **Access Control:** Restrict access to these endpoints to authorized monitoring infrastructure only (e.g., via Firewall/Security Groups).
- **Authentication:** Implement a reverse proxy (like Nginx or Apache) to add Basic Auth or TLS client certificates if the metrics must be accessed across networks.
## Detection
- **Indicators of Compromise:** Large spikes in unauthenticated HTTP traffic to port 9400 (default DCGM Exporter port) or 9100 (Node Exporter). Frequent service restarts or "Out of Memory" (OOM) kills of the `dcgm-exporter` process.
- **Detection Methods:** Audit external-facing IP addresses for exposed metrics at `hXXp://<host>:9400/metrics` and `hXXp://<host>:9400/debug/pprof/`.
## References
- **NVIDIA Advisory:** hXXps://nvidia[.]custhelp[.]com/app/answers/detail/a_id/5857
- **Researcher Technical Analysis:** hXXps://lava[.]security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability
- **NVD Detail:** hXXps://nvd[.]nist[.]gov/vuln/detail/cve-2026-47483
- **Project Repository:** hXXps://github[.]com/nvidia/dcgm-exporter