CVE-2026-47483 is an uncontrolled resource consumption vulnerability affecting NVIDIA DCGM and NVIDIA DCGM Exporter on all platforms within the reported vulnerable version ranges. The flaw is present in the exposed /debug/pprof diagnostic endpoints, which lack sufficient rate limiting and access controls. An unauthenticated remote attacker can submit large numbers of concurrent profiling requests to these endpoints, causing excessive consumption of CPU, memory, and file descriptors. This can render the exporter service unresponsive or cause it to crash. The issue may also expose limited diagnostic information through profiling output, including internal stack trace data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An uncontrolled resource consumption vulnerability in NVIDIA DCGM Exporter that allows an unauthenticated attacker to abuse exposed /debug/pprof diagnostic endpoints with concurrent profiling requests, leading to denial of service and possible low-impact information disclosure.
A high-severity uncontrolled resource consumption vulnerability in NVIDIA DCGM Exporter /debug/pprof endpoints that can be triggered via concurrent unauthenticated profiling requests, potentially causing denial of service and information disclosure.
A denial-of-service and information disclosure vulnerability in NVIDIA DCGM Exporter /debug/pprof endpoints caused by uncontrolled resource consumption via concurrent unauthenticated profiling requests.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.