CVE-2026-47483 is an uncontrolled resource consumption vulnerability in NVIDIA DCGM Exporter's Go pprof diagnostic endpoints across all platforms. Missing request throttling and access controls allow unauthenticated attackers to submit concurrent profiling requests, some with caller-controlled durations, exhausting CPU, memory, and file descriptors. Exploitation can make the exporter unresponsive or crash it and may disclose profiling information. Resource pressure may also interfere with co-located AI workloads.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity denial-of-service vulnerability in Nvidia DCGM Exporter allows unauthenticated attackers to overwhelm and crash the GPU monitoring service, potentially disrupting AI training and inference workloads. Researchers identified approximately 2,100 internet-exposed GPU servers across around 300 organizations, with hundreds potentially vulnerable. The content does not report confirmed exploitation.
A high-severity resource-exhaustion vulnerability in NVIDIA DCGM Exporter, rated CVSS 8.2. Exposed Go /debug/pprof/ profiling endpoints allow concurrent unauthenticated requests to exhaust memory and crash GPU monitoring. CPU and memory pressure may also disrupt training or inference workloads on the same host, particularly without strict resource limits.
A high-severity resource-exhaustion vulnerability in NVIDIA DCGM Exporter, reachable through pprof, that allows unauthenticated remote attackers to crash GPU monitoring and potentially disrupt AI workloads. Researchers identified more than 2,100 publicly exposed GPU servers revealing telemetry from over 12,000 GPUs. NVIDIA fixed the vulnerability following responsible disclosure.
A high-severity denial-of-service vulnerability in Nvidia DCGM Exporter, rated CVSS 8.2. Concurrent unauthenticated requests to exposed Go profiling endpoints can exhaust memory and crash the exporter, interrupting GPU health monitoring. CPU and memory pressure could also affect AI training or inference workloads. Researchers identified approximately 2,100 publicly exposed DCGM Exporter servers; about 25 percent also exposed profiling data.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.