Vulnerabilities
Last updated 43 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers | High Risk 8.0 | 19 days ago | 2 days ago |
grpc
|
Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding | Unknown | 3 months ago | 3 days ago |
grpc
|
Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc | Unknown | 3 months ago | 3 days ago |
grpc
|
Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc | Unknown | 3 months ago | 3 days ago |
|
|
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs | Low Risk 3.0 | 10 days ago | 10 days ago |
|
|
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning | Medium Risk 6.0 | 10 days ago | 10 days ago |
|
|
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | High Risk 8.0 | 26 days ago | 12 days ago |
|
|
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion | Medium Risk 6.0 | 19 days ago | 12 days ago |
|
|
Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc | Unknown | 12 days ago | 12 days ago |
|
|
Server panic via missing authority or Host headers in google.golang.org/grpc | Unknown | 12 days ago | 12 days ago |
|
|
Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc | Unknown | 12 days ago | 12 days ago |
|
|
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | High Risk 8.0 | 2 months ago | 18 days ago |
|
|
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash | High Risk 7.5 | 3 months ago | 18 days ago |
|
|
@grpc/grpc-js: A malformed request can cause a server crash | High Risk 7.5 | 3 months ago | 18 days ago |
|
|
gRPC-Go has an authorization bypass via missing leading slash in :path | Critical 9.1 | 6 months ago | 18 days ago |
|
|
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability | High Risk 7.5 | 1 year ago | 18 days ago |
|
|
Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go | Low Risk 3.0 | 2 years ago | 18 days ago |
|
|
@grpc/grpc-js can allocate memory for incoming messages well above configured limits | Medium Risk 5.3 | 2 years ago | 18 days ago |
|
|
go-grpc-compression has a zstd decompression bombing vulnerability | High Risk 7.5 | 2 years ago | 18 days ago |
|
|
Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC | High Risk 8.2 | 2 years ago | 18 days ago |
|
|
otelgrpc DoS vulnerability due to unbound cardinality metrics | High Risk 7.5 | 2 years ago | 18 days ago |
|
|
gRPC-Go HTTP/2 Rapid Reset vulnerability | High Risk 7.5 | 2 years ago | 18 days ago |
|
|
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms) | High Risk 7.5 | 3 years ago | 18 days ago |
|
|
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms) | High Risk 7.5 | 3 years ago | 18 days ago |
|
|
gRPC connection termination issue | Medium Risk 5.3 | 3 years ago | 18 days ago |
|
|
gRPC connection termination issue | Medium Risk 5.3 | 3 years ago | 18 days ago |
|
|
gRPC connection termination issue | Medium Risk 5.3 | 3 years ago | 18 days ago |
|
|
Connection confusion in gRPC | High Risk 7.4 | 3 years ago | 18 days ago |
|
|
Connection confusion in gRPC | High Risk 7.4 | 3 years ago | 18 days ago |
|
|
Connection confusion in gRPC | High Risk 7.4 | 3 years ago | 18 days ago |
|
|
gRPC Reachable Assertion issue | High Risk 7.5 | 3 years ago | 18 days ago |
|
|
gRPC Reachable Assertion issue | High Risk 7.5 | 3 years ago | 18 days ago |
|
|
gRPC Reachable Assertion issue | High Risk 7.5 | 3 years ago | 18 days ago |
grpc
|
gRPC Erlang package has unbounded gzip decompression (decompression bomb) | High Risk 8.0 | 1 month ago | 1 month ago |
grpc
|
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads | Critical 9.5 | 1 month ago | 1 month ago |
grpc
|
gRPC Erlang package's path bindings are overridable by query string and request body | High Risk 8.0 | 1 month ago | 1 month ago |
grpc
|
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3` | High Risk 8.0 | 1 month ago | 1 month ago |
grpc
|
grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1 | Unknown | 3 months ago | 1 month ago |
|
|
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc | Unknown | 2 months ago | 2 months ago |
| github.com/grpc/grpc-swift | Uncontrolled Resource Consumption in LengthPrefixedMessageReader | High Risk 7.5 | 3 years ago | 2 months ago |
| github.com/grpc/grpc-swift | Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec | High Risk 8.0 | 3 years ago | 2 months ago |
| github.com/grpc/grpc-swift | Uncontrolled Recursion in HTTP2ToRawGRPCServerCodec | Medium Risk 6.0 | 3 years ago | 2 months ago |
|
|
Excessive Iteration in gRPC | High Risk 7.5 | 3 years ago | 2 months ago |
|
|
Excessive Iteration in gRPC | High Risk 7.5 | 3 years ago | 2 months ago |
|
|
Excessive Iteration in gRPC | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
gRPC Reachable Assertion issue | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
gRPC connection termination issue | Medium Risk 5.3 | 2 months ago | 2 months ago |
|
|
Connection confusion in gRPC | High Risk 7.4 | 2 months ago | 2 months ago |
|
|
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms) | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
Malicious code in github.com/BufferZoneCorp/grpc-client (Go) | Unknown | 4 months ago | 4 months ago |
Page 1