Opens in a new tab
vmblog logo 2024 wht (updated)

Lava Research Finds Thousands of Exposed AI GPU Servers, Uncovers High-Severity NVIDIA Vulnerability That Can Disrupt Them Remotely

Share: 

David Marshall | Published: October 9, 2026

Lava released new research revealing widespread exposure across the infrastructure powering the AI boom. During the research, Lava uncovered a high-severity vulnerability in NVIDIA’s DCGM Exporter, a widely deployed tool used to monitor the health and performance of GPUs across AI servers and clusters. The finding highlights a growing security gap in AI infrastructure: companies are spending millions on GPUs while leaving critical systems exposed. Those exposures can reveal how AI environments are built and allow attackers to disrupt them.

Lava found that the service was frequently exposed directly to the public internet, turning an internal monitoring component into a publicly accessible attack surface.The vulnerability allowed anyone who could reach an exposed instance to exploit it, triggering uncontrolled resource consumption on the GPU server, denial of service, and information disclosure. NVIDIA assigned the issue CVE-2026-47483, rated it 8.2 (High), and released a fix.

“Neoclouds are racing to add GPU capacity, and customers are racing to use it,” said Yakir Kadkoda, CTO and Co-Founder at Lava. “That speed is creating security gaps on both sides – providers are moving faster than they can harden the environment, while customers often don’t know exactly what they’re inheriting or exposing.”

Lava researchers identified roughly 2,100 publicly accessible NVIDIA DCGM Exporter hosts exposing more than 12,000 unique GPUs. Every identified host exposed GPU telemetry to the public internet without authentication. Based on approximate market values for the models observed, Lava estimates the exposed GPUs represented more than $100 million in hardware.

The exposed systems included NVIDIA’s latest Blackwell Ultra B300 GPUs, alongside H200s and H100s used to power large-scale AI workloads, as well as consumer RTX 5090 and 4090 systems. Anyone on the internet could see what hardware organizations were running, how heavily it was being used, and what their AI infrastructure looked like.

While investigating the exposed systems, Lava found that roughly a quarter of the public NVIDIA DCGM Exporter instances also exposed internal Go profiling endpoints. Researchers initially believed this was an operator configuration error, but reproduced the behavior using NVIDIA’s official DCGM Exporter container. Lava researchers demonstrated that an unauthenticated attacker could remotely exhaust system resources and crash the NVIDIA DCGM Exporter, cutting off GPU monitoring. The resulting CPU and memory pressure could also affect AI training or inference workloads running on the same server. NVIDIA fixed the issue in version 4.8.2, and operators should upgrade to that version or later.

The exposure extended beyond GPUs into other critical layers of AI data centers. Lava identified 12,096 publicly accessible servers exposing data through node_exporter, a tool used to monitor server health. The exposed data included server models, operating systems, firmware versions, hostnames, storage paths and networking hardware commonly used in GPU clusters, revealing how environments were built and configured. For attackers, this can provide a head start by exposing what technologies are in use and where known weaknesses may exist Lava identified publicly exposed monitoring services on customer infrastructure across major neocloud and GPU cloud providers, including Nebius, Voltage Park, Lambda, Northern Data and DigitalOcean. Providers indicated that most of the exposed services had been deployed by their customers.

Lava reported the findings to the affected providers, who worked with customers to remediate the exposures. Lava recommends preventing NVIDIA DCGM Exporter, Node Exporter and Prometheus services from being directly reachable from the public internet and restricting them to authorized monitoring infrastructure.

The full report can be found at: https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability