Thursday, 8 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Man Utd held back as Spurs spent big - Different strategies collide on Saturday› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Man Utd held back as Spurs spent big - Different strategies collide on Saturday
Technology

High-severity Nvidia bug could crash GPU monitoring on exposed servers

The Register ·
High-severity Nvidia bug could crash GPU monitoring on exposed servers

Researchers found thousands of GPU servers exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring service and disrupt AI workloads.

DCGM Exporters read telemetry from the GPUs on a host, including its hardware, utilization, memory usage, power consumption, and error events.

Each GPU has its own unique ID, or UUID, and all of these metrics are exposed in plaintext over HTTP.

This exposure provides would-be attackers with detailed information useful for reconnaissance, including mapping GPU infrastructure, identifying potentially vulnerable systems, and monitoring workload activity.

Michael Katchinskiy, a researcher at datacenter security startup Lava, found and reported the bug in the GPU health and performance monitoring service.

In September, the GPU giant Nvidia released a fix for the flaw, tracked as CVE-2026-47483, and gave it an 8.2 CVSS high-severity rating.

“Once we realized how much these endpoints revealed, the next question was: How many of them are exposed to the internet?” Katchinskiy said in a Thursday blog.

So the researchers started scanning the internet for exposed DCGM Exporters.

And the scale of exposure proved “especially significant,” he wrote.

Over the course of four scans between March and May, the threat hunters found about 2,100 GPU servers exposing DCGM Exporter metrics to the open internet.

These included 12,000 GPU UUIDs.

None of these required authentication.

The hosts belonged to about 300 organizations, according to Katchinskiy, and nearly half - 5,274 of the exposed GPUs, or 44 percent of the total - were located in the US.

These GPUs represented about $100 million in hardware, and included Nvidia Blackwell Ultra B300 GPUs, H200s, and H100s - used to run large-scale AI workloads - plus consumer RTX 5090 and 4090 systems.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›