Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Grpc CRITICAL 9.1
CVE-2026-33186

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of …

Fix: 1.79.3+
Fix from $2,300 2026-03-20
Grpc HIGH 7.5
CVE-2024-11407

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_…

Fix: 1.66.1+
Fix from $1,950 2024-11-26
Grpc MEDIUM 5.3
CVE-2024-7246

It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients…

Fix: 1.58.3 / 1.59.5+
Fix from $1,600 2024-08-06
Grpc HIGH 7.5
CVE-2023-4785

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause…

Fix: 1.53.2 / 1.54.3+
Fix from $1,950 2023-09-13
Grpc HIGH 7.5
CVE-2023-33953

gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional…

Fix: 1.53.2 / 1.54.3+
Fix from $1,950 2023-08-09
Grpc HIGH 7.5
CVE-2023-1428

There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called …

Fix: 1.53.0+
Fix from $1,950 2023-06-09
Grpc HIGH 7.5
CVE-2023-32731

When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to a…

Fix: 1.55.0+
Fix from $1,950 2023-06-09
Grpc CRITICAL 9.8
CVE-2020-7768

The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

Fix: 1.1.8 / 1.24.2+
Fix from $2,300 2020-11-11
Grpc CRITICAL 9.8
CVE-2017-9431

Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.

Fix: after 1.2.2
Fix from $2,300 2017-06-05
Grpc CRITICAL 9.8
CVE-2017-8359

Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/…

Fix: after 1.2.1
Fix from $2,300 2017-04-30
Grpc CRITICAL 9.8
CVE-2017-7860

Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client…

Fix: after 1.1.2
Fix from $2,300 2017-04-14
Grpc CRITICAL 9.8
CVE-2017-7861

Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.

Fix: after 1.1.2
Fix from $2,300 2017-04-14