NVIDIA DCGM Exporter – Uncontrolled Resource Consumption Denial of Service (CVE-2026-47483)
Scope: NVIDIA DCGM Exporter
Severity: Medium
An uncontrolled resource consumption vulnerability exists in the NVIDIA DCGM Exporter due to a lack of rate limiting and access controls on the /debug/pprof diagnostic endpoints. An unauthenticated attacker can exploit this configuration by submitting a high volume of concurrent profiling requests. This attack exhausts system resources, including CPU, memory, and file descriptors, causing the exporter service to become unresponsive or crash. Consequently, GPU monitoring, telemetry, and alerting capabilities are severely disrupted. Furthermore, prolonged exploitation can destabilize the underlying host system, negatively impacting other co-located services, and may result in low-impact information disclosure if profiling data leaks internal stack traces. Organizations must apply the latest patched version provided by NVIDIA. Network administrators must restrict access to the /debug/pprof endpoints using robust firewall rules, implement rate limiting and mandatory authentication (such as basic auth or API keys), and ensure the exporter is isolated on an internal network segment accessible solely by trusted monitoring infrastructure.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the NVD Record for CVE-2026-47483 and apply the necessary updates.