Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host heade…
CVE-2026-84303MediumgRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are…
CVE-2026-84304HighgRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate…
CVE-2026-48853CriticalgRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
CVE-2026-48599HighgRPC Erlang package's path bindings are overridable by query string and request body
CVE-2026-48854HighgRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
CVE-2026-53430HighgRPC Erlang package has unbounded gzip decompression (decompression bomb)
GO-2026-6061NoneVulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
GHSA-hrxh-6v49-42gfHighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
CVE-2026-48069High· 7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-48068High· 7.5@grpc/grpc-js: A malformed request can cause a server crash
CVE-2026-33186Critical· 9.1PoCgRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…
CVE-2023-4785High· 7.5Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
CVE-2023-32732Medium· 5.3gRPC connection termination issue
CVE-2023-1428High· 7.5gRPC Reachable Assertion issue
CVE-2023-32731High· 7.4Connection confusion in gRPC
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.