Skip to content
Security & Trust

Open GPU monitoring leaked hardware details; about a quarter had a crash flaw

About 2,100 hosts served NVIDIA GPU data with no login; a quarter also exposed the pprof flaw (CVE-2026-47483).

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Open GPU monitoring leaked hardware details; about a quarter had a crash flaw
In brief
  • Lava Security found about 2,100 hosts serving NVIDIA DCGM Exporter metrics with no login. They covered more than 12,000 unique GPUs, seen in four scans from March to May 2026.
  • About a quarter of those hosts also served pprof debug pages tied to CVE-2026-47483 (CVSS 8.2), which let unauthenticated requests crash GPU monitoring.
  • Check whether any exporter is reachable from the internet, and upgrade DCGM Exporter to 4.8.2 or later.

Teams tend to guard the model and the data first. This research suggests the dashboard that watches the hardware needs the same care. New findings from Lava Security show it can tell a stranger a great deal about what you run and how hard you run it.

What Lava Security found

NVIDIA DCGM Exporter reads temperature, utilization, memory and power from GPUs. It publishes those readings over HTTP so a monitoring system such as Prometheus can collect them.

Lava's researchers looked for servers that publish this data openly. They ran four scans from March to May 2026. About 2,100 hosts turned up. Every one used plain HTTP. None asked for a login.

12,000+
Unique GPUs reporting to the open internet
Source: Lava Security research (October 8, 2026)

Lava estimates the hardware was worth $100 million. Half of the cards were data center accelerators, such as H100s and H200s. The remaining half were built for gamers and desktop workstations, chiefly the RTX 4090 and 5090. The scans also found 312 B200 and 32 B300 GPUs. Those are current-generation Blackwell parts.

Why a metrics page works like a map

Each GPU in the data carries its own unique ID. An observer can follow the same card over time, even if its hostname changes. The data names the exact model and shows how busy it is. Repeated readings show when work starts and stops.

Some setups add Kubernetes labels. Their pod and namespace names can reveal project names. Busy and idle readings may point to training or to inference. Lava says they do not settle the question.

Hardware and software details still help an attacker. They narrow the hunt for known flaws that fit the target.

The flaw: a debugging tool left reachable

The crash risk did not apply to every open page. About a quarter of the exposed hosts also served Go's /debug/pprof/ pages. Pprof is a profiling tool built into the Go language. It is meant for internal debugging.

Some of its pages keep a request open for as long as the caller asks. Many such requests at once, with no login, can push memory use up. In the end the exporter crashes.

Lava first assumed operators had set things up wrongly. It then reproduced the behavior on NVIDIA's official container, unchanged. So any setup that makes the exporter reachable over the network may expose pprof too.

Lava reported the problem to NVIDIA. NVIDIA tracks it as CVE-2026-47483, scored 8.2 on the CVSS severity scale, a High rating. NVIDIA also issued an advisory.

The harm has two parts. A crashed exporter leaves operators blind to GPU health. The extra load could also slow other jobs on the same server, especially where resource limits are loose. Lava tested the exhaustion in a controlled setting. It did not try it on the public systems it found.

About 25%
Exposed DCGM hosts also serving pprof endpoints
Source: Lava Security research (October 8, 2026)

Who owns the exposure

Lava sorted the exposed GPUs by type of operator. Consumer GPU and mining farms held 35%. Neoclouds, which rent out GPU capacity, held 25%. Hosting and colocation firms held 19%. Hyperscalers held 6%.

By country, the United States held 44% of exposed GPUs. Romania held 17% and China 16%.

One provider shows how ownership gets blurry. Voltage Park had the largest group Lava documented. It had 672 open server-monitoring hosts and 71 open GPU-monitoring hosts. Voltage Park said all the GPU ones, and most of the others, were deployed by customers.

Voltage Park, citing the shared responsibility model, says securing those services is the customer's job. Even so, its security team investigated and contacted the affected customers.

A separate tool, Node Exporter, reports on server hardware. Lava counted 12,096 open ones that also showed data from NVIDIA/Mellanox network cards. A single endpoint was enough to identify a Dell PowerEdge XE9680 server. It also gave the operating system version, the BIOS and an active 400 Gb/s port.

The idle-hardware surprise

In each of the four scans, roughly 60% of the GPUs showed 0% utilization. Lava had expected the cards to be running flat out. The scans are snapshots. They cannot say why the cards sat idle.

Roughly 60%
GPUs reporting 0% utilization in each of four scans
Source: Lava Security research (October 8, 2026)

What this shows

The lesson here is that monitoring is part of the attack surface. Teams treat metrics as harmless exhaust. But a metrics page is a live inventory and a usage log. For the hosts that also served pprof, it was a way to switch off the instruments too. That matters most when the hardware is costly and scarce.

Questions for your team

Ask whether any Node Exporter, DCGM Exporter or Prometheus endpoint can be reached from outside your network. Ask who checks, and how often. Lava advises binding exporters to loopback or private interfaces. It also advises firewall rules or security groups so only monitoring systems can reach them.

Move DCGM Exporter to version 4.8.2 or newer. Keep the --enable-pprof switch off unless someone truly needs profiling. In current versions, profiling is opt-in. If you rent GPUs from a neocloud, ask which monitoring services your contract makes your job.

A dashboard is built to be seen. The question is by whom.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: lava.security.

Share this insight