Executive brief
NVIDIA DCGM Exporter is a tool used to monitor the health and performance of NVIDIA GPUs in data centers and cloud environments. A security flaw in its debugging interface allows an unauthorized person to overwhelm the system with requests, potentially causing the monitoring service to crash or leak internal information. This could disrupt GPU performance monitoring and impact the stability of infrastructure management tools.
Technical details
NVIDIA DCGM Exporter is vulnerable to uncontrolled resource consumption (CWE-770) via its /debug/pprof endpoints. An unauthenticated remote attacker can exploit this by submitting concurrent profiling requests, which exhausts system resources. This can result in a denial of service (DoS) condition for the exporter and potentially lead to the disclosure of sensitive internal information. The vulnerability affects DCGM Exporter versions up to 4.8.2 and DCGM versions up to 4.5.2 across all platforms.
Affected products
- NVIDIA DCGM Exporter 0.0 to 4.8.2
- NVIDIA DCGM 0.0 to 4.5.2
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory