Nvidia DCGM Exporter flaw can crash GPU monitoring, fixed in 4.8.2
EditorialBy TrustList Editorial
Researchers found about 2,100 internet-exposed GPU servers in scans between March and May. Nvidia rates the bug 8.2 and shipped the fix in September; no attacks are reported.
- Cybersecurity
- Vulnerability Management
- Monitoring
- Data Center
About Nvidia DCGM Exporter flaw can crash GPU monitoring, fixed in 4.8.2
Nvidia DCGM Exporter flaw can crash GPU monitoring, fixed in 4.8.2
8 October 2026: Nvidia has fixed CVE-2026-47483, a high-severity flaw in DCGM Exporter, the service that reports GPU health and performance data to monitoring systems. An unauthenticated attacker who can reach the exporter can crash it by sending many concurrent requests, which exhausts its memory. Nvidia scores the flaw 8.2 and the fix is in version 4.8.2; The Register reports no sign of active exploitation.
Not yet independently verified. We could not open Nvidia's advisory, which returns an authorisation error, so the score, fixed version and exposure figures come from The Register's report of it. The advisory date is not confirmed. We will update this when it can be confirmed, and remove this note.
The outcome is a loss of visibility rather than a data breach. When the exporter falls over, dashboards and alerts that depend on it go quiet, and a cluster can keep running jobs while operators lose sight of temperatures, utilisation and errors on the GPUs underneath.
How exposed the exporters are
The Register says researchers scanning the internet between March and May found about 2,100 GPU servers exposing the service. The article presents that number as an exposure risk, not as evidence that anyone attacked them. Nvidia released the fix in September, so the patch has been available for several weeks before the public write-up.
Exporters of this kind usually answer on a plain HTTP port and carry no authentication by default, which is why reachability is the main variable. A server reachable only from an internal monitoring network is in a very different position from one answering on a public address.
Finding every copy
The remedy is to upgrade DCGM Exporter to 4.8.2 or later. Before that, find every GPU host that runs the exporter, including those inside container images and Kubernetes DaemonSets, since a pinned older image will keep the vulnerable version in service after the host is updated.
Then check whether the exporter port is reachable from outside your monitoring network, and restrict it with firewall or network policy rules if it is. Our network monitoring software category lists eight products, though GPU telemetry is usually gathered through exporters like this one rather than through those tools.
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Monitoring
- Data Center
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.