CVE-2023-33953High· 7.5▾ TwilightExcessive Iteration in gRPC
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.5%
gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks:
The unbounded CPU consumption is down to a copy that occurred per-input-block in the parser, and because that could be unbounded due to the memory copy bug we end up with an O(n^2) parsing loop, with n selected by the client.
The unbounded memory buffering bugs:
grpcio < 1.53.2grpcio >= 1.54.0, < 1.54.3grpcio >= 1.55.0, < 1.55.2grpcio >= 1.56.0, < 1.56.2grpc < 1.53.2grpc >= 1.54.0, < 1.54.3grpc >= 1.55.0, < 1.55.2grpc >= 1.56.0, < 1.56.2Upgrade to a patched release:
grpcio 1.53.2grpcio 1.54.3grpcio 1.55.2grpcio 1.56.2grpc 1.53.2grpc 1.54.3grpc 1.55.2grpc 1.56.2