Skip to main content

Lava reports exposed GPU metrics and a high-severity NVIDIA flaw

10 OCTOBER 2026·2 MIN READ·4 SOURCES

Lava says scans found thousands of hosts exposing GPU metrics without authentication, and it also reported a high-severity flaw in NVIDIA’s DCGM Exporter. The company says it released its research on October 8.

Lava reports exposed GPU metrics and a high-severity NVIDIA flaw

Key takeaways · 4

  • 01

    Lava found roughly 2,100 hosts exposing metrics from more than 12,000 GPUs across four scans.

  • 02

    None of the hosts required authentication to access their metrics, and the metrics were served over plaintext HTTP.

  • 03

    NVIDIA assigned the reported DCGM Exporter flaw CVE-2026-47483 and a CVSS score of 8.2, rated High.

  • 04

    Lava recommends upgrading DCGM Exporter to version 4.8.2 or later and disabling pprof unless needed.

What the scans found

Lava says four scans conducted between March and May 2026 found roughly 2,100 hosts exposing metrics from more than 12,000 unique GPUs.[2] The exposed systems included B300, H200 and H100 data-center GPUs, along with RTX 5090 and 4090 cards.[2] Lava says the exporters appeared on just over 2,000 hosts associated with nearly 300 organizations.[2] The United States accounted for 5,274 exposed GPUs, or 44 percent; Romania had 2,054 and China 1,967.[2]

What exposure can reveal

Lava says none of the exposed hosts required authentication to access their metrics, and that the metrics were served over plaintext HTTP.[2] It estimates the exposed GPUs represented about $100 million in hardware.[2] Roughly 60 percent of the GPUs reported zero utilization in each of the four scans, according to Lava.[2] That is a reading from those scans, not evidence in itself that the GPUs remained idle at other times. Lava says the metrics can reveal hardware models, usage levels and details of surrounding AI infrastructure.[2]

The separate exporter flaw

Lava says it reported a flaw in NVIDIA’s DCGM Exporter to NVIDIA, which assigned it CVE-2026-47483 and a CVSS score of 8.2, rated High.[2] NVIDIA’s vulnerability description says a successful exploit could cause denial of service and information disclosure.[3] Lava says about a quarter of the exposed DCGM hosts also served Go profiling endpoints alongside their metrics endpoints.[2] It reproduced the behavior using NVIDIA’s official DCGM Exporter container without modifying it, and tested resource exhaustion in a controlled environment—not against the public deployments it observed.[2]

Mitigation and response

NVIDIA published its security bulletin for the flaw on July 28, 2026.[4] Lava recommends upgrading DCGM Exporter to version 4.8.2 or later and disabling pprof unless it is needed.[2] It says CPU and memory pressure from an attack could slow a host and interfere with training or inference workloads running alongside the exporter.[2] Lava advises operators not to expose Node Exporter, DCGM Exporter or Prometheus directly to the public internet without a specific need and access controls.[2] Voltage Park’s security team investigated Lava’s report and contacted affected customers.[2]

GPU monitoring can expose operational details as well as measurements, so teams should treat monitoring endpoints as sensitive infrastructure. Operators can use Lava’s findings to review internet exposure, access controls, exporter versions and whether profiling endpoints are necessary.

Why it matters
Story quiz

Test yourself on this story — 1 question.

Create a free account to take the quiz, earn XP, and get a daily session built for your industry.

Take the quiz

How this developed

  1. 10 October 2026

    Lava reports exposed GPU metrics and a high-severity NVIDIA flaw

Sources

AI fluency, one session a day, built for your work.