Description
NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
Published: 2026-07-28
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA DCGM Exporter for all platforms has a flaw in the /debug/pprof endpoints that permits an attacker to send concurrent, unauthenticated profiling requests, causing uncontrolled resource consumption that can result in a denial‑of‑service condition and potentially expose profiling data. The vulnerability is a classic uncontrolled resource consumption flaw (CWE‑770) targeting the profiling subsystem.

Affected Systems

All NVIDIA DCGM and DCGM Exporter deployments across supported platforms are affected. No specific version range is listed in the advisory, so any installation that contains the /debug/pprof endpoints is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.2 indicates a high‑severity impact, while the EPSS score of less than 1% suggests a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector involves unauthenticated HTTP profiling requests, it is inferred that the exploit can be performed remotely over the network. Successful exploitation would consume system resources, shutting down services and, if not mitigated, can reveal profiling data to the attacker.

Generated by OpenCVE AI on August 4, 2026 at 12:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest NVIDIA DCGM Exporter release that contains the fix; apply the vendor-provided patch as soon as it becomes available.
  • Restrict access to the /debug/pprof endpoint by firewalling or disabling the endpoint in production environments to prevent unauthenticated use.
  • Deploy rate limiting or throttling mechanisms on the endpoint to limit the number of concurrent profiling requests and protect system resources.
  • Continuously monitor system metrics and logs for abnormal profiling activity, and respond promptly to any surge in resource usage.

Generated by OpenCVE AI on August 4, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption in NVIDIA DCGM Exporter via Unauthenticated Profiling Endpoints

Sun, 02 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption in NVIDIA DCGM Exporter via Unauthenticated Profiling Endpoints

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia dcgm
Nvidia dcgm Exporter
Vendors & Products Nvidia
Nvidia dcgm
Nvidia dcgm Exporter

Tue, 28 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Nvidia Dcgm Dcgm Exporter
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-07-28T16:48:18.878Z

Reserved: 2026-05-19T19:55:39.687Z

Link: CVE-2026-47483

cve-icon Vulnrichment

Updated: 2026-07-28T16:48:10.347Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T16:18:15.003

Modified: 2026-07-28T17:16:45.823

Link: CVE-2026-47483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:00:11Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling