Nvidia Fixes High-Severity GPU Monitoring Vulnerability Affecting AI Servers
Nvidia has addressed a high-severity vulnerability in its GPU monitoring software that could allow unauthenticated attackers to disrupt services on affected servers. Tracked as CVE-2026-47483, the flaw affects Nvidia DCGM Exporter, a tool used to monitor GPU health, utilisation, memory, power consumption and other performance metrics across AI computing infrastructure.
Nvidia published its security advisory on July 28, 2026. The vulnerability received renewed attention in October after researchers highlighted internet-exposed GPU servers that could be at risk.
How the Vulnerability Works
The flaw involves the /debug/pprof profiling endpoints in DCGM Exporter. According to Nvidia's advisory, attackers could submit concurrent profiling requests without authentication, triggering uncontrolled resource consumption.
The vulnerability carries a CVSS score of 8.2 out of 10, placing it in the high-severity category. Successful exploitation could cause denial of service and information disclosure, potentially interrupting GPU monitoring and affecting administrators' visibility into server activity.
Exposed GPU Servers Raise Concerns
DCGM Exporter is commonly used in data centres and AI computing clusters to collect telemetry from Nvidia GPUs. When monitoring endpoints are exposed to the public internet, attackers may be able to access operational information or attempt to exploit vulnerable software.
Security researchers reported identifying thousands of internet-exposed servers providing GPU telemetry. Such exposure can reveal details about infrastructure and workload activity, making secure configuration an important part of protecting AI environments.
Nvidia Releases Software Updates
Nvidia's advisory identifies affected versions of DCGM and DCGM Exporter and recommends updating to the fixed releases. The advisory lists DCGM versions up to 4.5.2 as affected, with version 4.5.3 identified as the fix. For DCGM Exporter, the advisory lists affected versions up to 4.8.2.
Administrators should consult Nvidia's official security guidance, verify their installed versions and apply the appropriate updates. They should also restrict access to monitoring endpoints and avoid exposing debugging interfaces unnecessarily.
Implications for AI Infrastructure Security
The vulnerability highlights the importance of securing the supporting software around AI hardware. GPU servers are valuable infrastructure for model training and inference, but monitoring tools and administrative interfaces can also introduce risks when they are improperly configured or left unpatched.
For organisations operating large GPU clusters, timely patching and network access controls are essential to maintaining reliable monitoring and reducing opportunities for disruption.
