Lava reports exposed GPU metrics and a high-severity NVIDIA flaw
Lava says scans found thousands of hosts exposing GPU metrics without authentication, and it also reported a high-severity flaw in NVIDIA’s DCGM Exporter. The company says it released its research on October 8.

Key takeaways · 4
- 01
Lava found roughly 2,100 hosts exposing metrics from more than 12,000 GPUs across four scans.
- 02
None of the hosts required authentication to access their metrics, and the metrics were served over plaintext HTTP.
- 03
NVIDIA assigned the reported DCGM Exporter flaw CVE-2026-47483 and a CVSS score of 8.2, rated High.
- 04
Lava recommends upgrading DCGM Exporter to version 4.8.2 or later and disabling pprof unless needed.
What the scans found
Lava says four scans conducted between March and May 2026 found roughly 2,100 hosts exposing metrics from more than 12,000 unique GPUs.[2] The exposed systems included B300, H200 and H100 data-center GPUs, along with RTX 5090 and 4090 cards.[2] Lava says the exporters appeared on just over 2,000 hosts associated with nearly 300 organizations.[2] The United States accounted for 5,274 exposed GPUs, or 44 percent; Romania had 2,054 and China 1,967.[2]
What exposure can reveal
Lava says none of the exposed hosts required authentication to access their metrics, and that the metrics were served over plaintext HTTP.[2] It estimates the exposed GPUs represented about $100 million in hardware.[2] Roughly 60 percent of the GPUs reported zero utilization in each of the four scans, according to Lava.[2] That is a reading from those scans, not evidence in itself that the GPUs remained idle at other times. Lava says the metrics can reveal hardware models, usage levels and details of surrounding AI infrastructure.[2]
The separate exporter flaw
Lava says it reported a flaw in NVIDIA’s DCGM Exporter to NVIDIA, which assigned it CVE-2026-47483 and a CVSS score of 8.2, rated High.[2] NVIDIA’s vulnerability description says a successful exploit could cause denial of service and information disclosure.[3] Lava says about a quarter of the exposed DCGM hosts also served Go profiling endpoints alongside their metrics endpoints.[2] It reproduced the behavior using NVIDIA’s official DCGM Exporter container without modifying it, and tested resource exhaustion in a controlled environment—not against the public deployments it observed.[2]
Mitigation and response
NVIDIA published its security bulletin for the flaw on July 28, 2026.[4] Lava recommends upgrading DCGM Exporter to version 4.8.2 or later and disabling pprof unless it is needed.[2] It says CPU and memory pressure from an attack could slow a host and interfere with training or inference workloads running alongside the exporter.[2] Lava advises operators not to expose Node Exporter, DCGM Exporter or Prometheus directly to the public internet without a specific need and access controls.[2] Voltage Park’s security team investigated Lava’s report and contacted affected customers.[2]
GPU monitoring can expose operational details as well as measurements, so teams should treat monitoring endpoints as sensitive infrastructure. Operators can use Lava’s findings to review internet exposure, access controls, exporter versions and whether profiling endpoints are necessary.
Why it matters
Test yourself on this story — 1 question.
Create a free account to take the quiz, earn XP, and get a daily session built for your industry.
Take the quizHow this developed
10 October 2026
Lava reports exposed GPU metrics and a high-severity NVIDIA flaw
Sources
- Lava Finds Thousands of Exposed GPU Servers and a High-Severity NVIDIA Monitoring Flaw – Unite.AIunite.ai
- CVE-2026-47483: NVIDIA DCGM Exporter Vulnerability Exposes GPU Servers | LAVAlava.security
- NVD - CVE-2026-47483nvd.nist.gov
- High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring - Help Net Securityhelpnetsecurity.com