CVE-2023-32732Medium· 5.3▾ SunlitgRPC connection termination issue
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.5%
Last analysed / modified upstream
gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for -bin suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309.
io.grpc:grpc-protobuf >= 1.53.0, < 1.53.1grpcio >= 1.53.0, < 1.53.1grpc >= 1.53.0, < 1.53.1io.grpc:grpc-protobuf >= 1.54.0, < 1.54.2grpcio >= 1.54.0, < 1.54.2grpc >= 1.54.0, < 1.54.2Upgrade to a patched release:
io.grpc:grpc-protobuf 1.53.1grpcio 1.53.1grpc 1.53.1io.grpc:grpc-protobuf 1.54.2grpcio 1.54.2grpc 1.54.2Connected by shared product, vendor, weakness, or advisory.
CVE-2023-32731High· 7.4Connection confusion in gRPC
CVE-2023-1428High· 7.5gRPC Reachable Assertion issue
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC
CVE-2026-84303MediumgRPC-Go is the Go language implementation of gRPC
CVE-2026-84304HighgRPC-Go is the Go language implementation of gRPC
GO-2026-6061NoneVulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc