Nvidia Fixed High-Severity GPU Exporter Flaw

Nvidia addressed a security vulnerability in the DCGM Exporter that exposed thousands of GPU servers to potential crashes.

Updated on Oct. 8, 2026 in Cybersecurity

Isometric editorial illustration of stacked server blades in an industrial rack chassis, representing enterprise infrastructure security.
Nvidia released a security patch this September for the DCGM Exporter, addressing a critical vulnerability that allowed unauthorized parties to crash server monitoring services. AI Illustration. Upload story photo >

Live Poll

Do you trust that major technology companies are doing enough to secure their AI infrastructure?

In September 2026, Nvidia released a security fix for a high-severity vulnerability in the DCGM Exporter that allowed unauthenticated users to crash GPU monitoring services. Researchers previously identified 2,100 servers globally that exposed sensitive hardware telemetry data to the public internet.

Why it matters

The security flaw highlights risks associated with leaving infrastructure monitoring tools reachable from the internet without authentication. Exposed services allowed unauthorized parties to access plaintext hardware metrics and induce memory exhaustion by sending concurrent requests.

The vulnerability carries an 8.2 CVSS high-severity rating and impacts hardware including Blackwell Ultra B300, H200, H100, RTX 5090, and RTX 4090 units. Approximately 25 percent of the affected hosts also inadvertently exposed profiling data from the Go pprof tool.

The players

Nvidia

Nvidia is a prominent technology company that designs graphics processing units and data center hardware used globally.

Lava

Lava is a research firm that employs the security experts who identified and reported the vulnerability in the DCGM Exporter.

The details

The DCGM Exporter was found reading hardware utilization and power consumption metrics, exposing them in plaintext over HTTP to the public. Beyond the 12,000 exposed GPU UUIDs, researchers discovered 12,096 public Node Exporter hosts leaking OS configuration and server hardware data.

Timeline

  1. Researchers scanned the internet for exposed DCGM Exporters from March to May 2026.

  2. Nvidia released a fix for the vulnerability in September 2026.

The Tech Race

The incident highlights the growing security risks inherent in the rapid deployment of high-performance GPU clusters in public-facing data center environments. Security vulnerabilities in tools like the Nvidia DCGM Exporter demonstrate the need for standardized authentication protocols in hardware management.

Operators of GPU servers must immediately upgrade to DCGM Exporter version 4.8.2 or later to prevent unauthorized crashes and data exposure. Users should also ensure that monitoring services are protected by firewalls or authentication rather than left exposed to the public internet.

The takeaway

Security teams should audit all infrastructure monitoring services to ensure they are not directly accessible from the public internet. Proactive patch management and the implementation of robust access controls are essential for protecting high-value hardware telemetry.

Further reading

Learn more about the latest threats and defensive measures in the Cybersecurity section.

Source note: This article includes information reported by TheRegister.

Live Poll

Do you trust that major technology companies are doing enough to secure their AI infrastructure?