Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning Medium Risk 6.0 10 days ago 2 hours ago
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning in go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc Unknown 3 hours ago 2 hours ago
google.golang.org/grpc gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers High Risk 8.0 19 days ago 3 days ago
grpc Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding Unknown 3 months ago 3 days ago
grpc Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc Unknown 3 months ago 3 days ago
grpc Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc Unknown 3 months ago 3 days ago
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs Low Risk 3.0 10 days ago 10 days ago
google.golang.org/grpc gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation High Risk 8.0 26 days ago 13 days ago
google.golang.org/grpc gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion Medium Risk 6.0 19 days ago 13 days ago
google.golang.org/grpc Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc Unknown 13 days ago 13 days ago
google.golang.org/grpc Server panic via missing authority or Host headers in google.golang.org/grpc Unknown 13 days ago 13 days ago
google.golang.org/grpc Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc Unknown 13 days ago 13 days ago
google.golang.org/grpc gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities High Risk 8.0 2 months ago 18 days ago
@grpc/grpc-js @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash High Risk 7.5 3 months ago 18 days ago
@grpc/grpc-js @grpc/grpc-js: A malformed request can cause a server crash High Risk 7.5 3 months ago 18 days ago
google.golang.org/grpc gRPC-Go has an authorization bypass via missing leading slash in :path Critical 9.1 6 months ago 18 days ago
io.grpc:grpc-netty-shaded Netty affected by MadeYouReset HTTP/2 DDoS vulnerability High Risk 7.5 1 year ago 18 days ago
google.golang.org/grpc Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go Low Risk 3.0 2 years ago 18 days ago
@grpc/grpc-js @grpc/grpc-js can allocate memory for incoming messages well above configured limits Medium Risk 5.3 2 years ago 18 days ago
github.com/mostynb/go-grpc-compression go-grpc-compression has a zstd decompression bombing vulnerability High Risk 7.5 2 years ago 18 days ago
go.opentelemetry.io/collector/config/configgrpc Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC High Risk 8.2 2 years ago 18 days ago
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc otelgrpc DoS vulnerability due to unbound cardinality metrics High Risk 7.5 2 years ago 18 days ago
google.golang.org/grpc gRPC-Go HTTP/2 Rapid Reset vulnerability High Risk 7.5 2 years ago 18 days ago
grpcio Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms) High Risk 7.5 3 years ago 18 days ago
grpc Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms) High Risk 7.5 3 years ago 18 days ago
grpcio gRPC connection termination issue Medium Risk 5.3 3 years ago 18 days ago
io.grpc:grpc-protobuf gRPC connection termination issue Medium Risk 5.3 3 years ago 18 days ago
grpc gRPC connection termination issue Medium Risk 5.3 3 years ago 18 days ago
grpcio Connection confusion in gRPC High Risk 7.4 3 years ago 18 days ago
io.grpc:grpc-protobuf Connection confusion in gRPC High Risk 7.4 3 years ago 18 days ago
grpc Connection confusion in gRPC High Risk 7.4 3 years ago 18 days ago
grpcio gRPC Reachable Assertion issue High Risk 7.5 3 years ago 18 days ago
io.grpc:grpc-protobuf gRPC Reachable Assertion issue High Risk 7.5 3 years ago 18 days ago
grpc gRPC Reachable Assertion issue High Risk 7.5 3 years ago 18 days ago
grpc gRPC Erlang package has unbounded gzip decompression (decompression bomb) High Risk 8.0 1 month ago 1 month ago
grpc gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads Critical 9.5 1 month ago 1 month ago
grpc gRPC Erlang package's path bindings are overridable by query string and request body High Risk 8.0 1 month ago 1 month ago
grpc gRPC Erlang package has unbounded request body accumulation in `read_full_body/3` High Risk 8.0 1 month ago 1 month ago
grpc grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1 Unknown 3 months ago 1 month ago
google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Unknown 2 months ago 2 months ago
github.com/grpc/grpc-swift Uncontrolled Resource Consumption in LengthPrefixedMessageReader High Risk 7.5 3 years ago 2 months ago
github.com/grpc/grpc-swift Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec High Risk 8.0 3 years ago 2 months ago
github.com/grpc/grpc-swift Uncontrolled Recursion in HTTP2ToRawGRPCServerCodec Medium Risk 6.0 3 years ago 2 months ago
grpcio Excessive Iteration in gRPC High Risk 7.5 3 years ago 2 months ago
grpc Excessive Iteration in gRPC High Risk 7.5 3 years ago 2 months ago
grpcio Excessive Iteration in gRPC High Risk 7.5 2 months ago 2 months ago
grpcio gRPC Reachable Assertion issue High Risk 7.5 2 months ago 2 months ago
grpcio gRPC connection termination issue Medium Risk 5.3 2 months ago 2 months ago
grpcio Connection confusion in gRPC High Risk 7.4 2 months ago 2 months ago
grpcio Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms) High Risk 7.5 2 months ago 2 months ago