Threat reportVulnerabilityTL-2026-3057
Nvidia DCGM Exporter unauthenticated denial-of-service via /debug/pprof (CVE-2026-47483)
Nvidia DCGM Exporter unauthenticated denial-of-service via (TL-2026-3057) is a high-severity software vulnerability scored CVSS 8.2, first published 2026-10-08. It has no confirmed attribution, affects NVIDIA DCGM Exporter, references 1 CVE (CVE-2026-47483), maps to 7 MITRE ATT&CK techniques (T1190, T1499.004, T1592.001), and is covered by 9 detection rules and 12 indicators of compromise.
- CVSS
- 8.2/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 7MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-3057
- Threat ID
- TL-2026-3057
- Severity
- HIGH
- CVSS
- 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, cloud-services, infrastructure
- Target regions
- Global, North America
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Nvidia DCGM Exporter unauthenticated denial-of-service via
Malware and tooling: Prometheus, Shodan
How Nvidia DCGM Exporter unauthenticated denial-of-service via works
A high-severity flaw (CVSS 8.2) in NVIDIA DCGM Exporter, the Prometheus exporter for GPU health and performance metrics, lets unauthenticated network attackers exhaust memory and crash the exporter by sending many concurrent requests to its Go /debug/pprof endpoints. The crash blinds GPU monitoring and the resource pressure can affect co-located AI training or inference workloads. NVIDIA lists DCGM Exporter 4.8.2 as the updated version. No in-the-wild exploitation or public PoC has been reported.
CVE-2026-47483 affects the /debug/pprof endpoints of NVIDIA DCGM Exporter, which are Go runtime profiling handlers served alongside the /metrics endpoint (default port 9400, plaintext HTTP, no authentication). Some pprof endpoints keep each request open for a caller-specified duration, so many concurrent unauthenticated profiling requests drive memory consumption up until the exporter runs out of memory and crashes. NVIDIA classifies the weakness as CWE-770 (Allocation of Resources Without Limits or Throttling) and scores it CVSS v3.1 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H); NVD/INCIBE note possible denial of service and information disclosure. The researchers at Lava reproduced the behavior against NVIDIA's official, unmodified container; no PoC was published and they state they did not test against public deployments.
Impact is twofold. First, availability: a crashed exporter removes GPU health visibility (utilization, memory, power, XID errors), and the CPU/RAM pressure can slow the host and interfere with co-located training or inference jobs, especially when no resource limits are set. Second, exposure: the exposed metrics already disclose GPU model, utilization, memory use, power, NVLink traffic, XID errors, driver versions and Kubernetes pod, namespace and container labels.
Lava's Shodan-based scans (four scans, March-May 2026) found about 2,100 GPU servers across roughly 300 organizations exposing DCGM Exporter metrics to the internet without authentication, covering more than 12,000 GPU UUIDs (about 44% / 5,274 in the US, hardware including B300, H200, H100, RTX 5090 and RTX 4090). About 25% of exposed DCGM hosts also exposed Go /debug/pprof/ endpoints. Lava also found 12,096 publicly exposed Prometheus Node Exporter hosts leaking server model, OS, firmware, hostnames, storage paths and networking hardware. Providers named as having customer infrastructure exposed were Nebius, Voltage Park, Lambda, Northern Data and DigitalOcean; Lava reported the findings and the providers worked with customers to fix the exposures.
NVIDIA's bulletin (answer 5857, first released 2026-07-28, last updated 2026-09-03) lists DCGM Exporter 0.0 to 4.8.2 as affected with 4.8.2 as the updated version (the bulletin's range and fix overlap, so confirm against the current bulletin), and DCGM 0.0 to 4.5.2 affected with 4.5.3 fixed. Per Lava, profiling is opt-in in current versions via --enable-pprof. Mitigations: upgrade, bind exporters to loopback or a private interface, firewall to authorized monitoring infrastructure only, protect Prometheus the same way, do not enable --enable-pprof unless required, and set resource limits. The Register reports no observed in-the-wild exploitation.
MITRE ATT&CK techniques used in TL-2026-3057
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.004 Application or System Exploitation
Reconnaissance
T1592.001 Hardware; T1592.002 Software; T1595.002 Vulnerability Scanning; T1596.005 Scan Databases
Discovery
Affected products and versions in Nvidia DCGM Exporter unauthenticated denial-of-service via
- NVIDIA — DCGM Exporter
Vulnerable versions: 0.0 through 4.8.2 (per NVIDIA bulletin)
Fixed in: 4.8.2 or later - NVIDIA — DCGM
Vulnerable versions: 0.0 through 4.5.2
Fixed in: 4.5.3
Remediation for Nvidia DCGM Exporter unauthenticated denial-of-service via
Patches
- Upgrade NVIDIA DCGM Exporter to 4.8.2 or later
- Upgrade NVIDIA DCGM to 4.5.3 or later
Immediate actions
- Do not expose DCGM Exporter, Node Exporter or Prometheus directly to the public internet; bind to loopback or a private interface
- Restrict access (firewall rules, security groups) so only authorized monitoring infrastructure can reach port 9400
- Do not enable --enable-pprof unless profiling is explicitly required
Workarounds
- Restrict or block /debug/pprof paths at a reverse proxy or network layer
Longer-term hardening
- Set CPU and memory resource limits on the exporter so exhaustion cannot starve co-located training or inference workloads
- Protect Prometheus query APIs and target pages with the same network restrictions
- Alert on loss of GPU metrics scrape targets and on external requests to /debug/pprof/
CVEs associated with Nvidia DCGM Exporter unauthenticated denial-of-service via
CVE-2026-47483
Weaknesses (CWE) in Nvidia DCGM Exporter unauthenticated denial-of-service via
Timeline of Nvidia DCGM Exporter unauthenticated denial-of-service via
- Lava begins four Shodan scans (March-May 2026) finding about 2,100 GPU servers across ~300 organizations exposing DCGM Exporter metrics with no authentication
- Last of Lava's four exposure scans completes (May 2026); ~12,000 GPU UUIDs and 12,096 Node Exporter hosts observed
- NVIDIA publishes security bulletin 5857 (Revision 1.0) for CVE-2026-47483; NVD and CVE.org records published the same day with CVSS 3.1 8.2
- NVIDIA bulletin last updated, listing DCGM Exporter 4.8.2 and DCGM 4.5.3 as updated versions
- No in-the-wild exploitation or public PoC reported at time of disclosure
- Lava publishes its research blog post crediting researcher Michael Katchinskiy; The Register reports the bug the same day
Sources cited for Nvidia DCGM Exporter unauthenticated denial-of-service via
- High-severity Nvidia bug could crash GPU monitoring on exposed servers
- NVIDIA Security Bulletin: NVIDIA DCGM Exporter (answer 5857)
- NVD: CVE-2026-47483
- Lava research: CVE-2026-47483 Nvidia DCGM Exporter vulnerability
- INCIBE-CERT early warning: CVE-2026-47483
- NVIDIA product-security repository, bulletin 5857
- CVE.org record: CVE-2026-47483
- NixOS security tracker: NIXPKGS-2026-2306
Detection coverage for TL-2026-3057
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3057 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.