CVE-2023-4785High· 7.5▾ TwilightDenial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.7%
Last analysed / modified upstream
0.7% → 0.8%
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.
grpc >= 1.56.0, < 1.56.2grpc >= 1.55.0, < 1.55.3grpc >= 1.54.0, < 1.54.3grpc >= 1.53.0, < 1.53.2grpcio >= 1.55.0, < 1.55.3grpcio >= 1.54.0, < 1.54.3grpcio >= 1.53.0, < 1.53.2Upgrade to a patched release:
grpc 1.56.2grpc 1.55.3grpc 1.54.3grpc 1.53.2grpcio 1.55.3grpcio 1.54.3grpcio 1.53.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48853CriticalgRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
CVE-2026-48599HighgRPC Erlang package's path bindings are overridable by query string and request body
CVE-2026-48854HighgRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
CVE-2026-53430HighgRPC Erlang package has unbounded gzip decompression (decompression bomb)
CVE-2026-33186Critical· 9.1gRPC-Go is the Go language implementation of gRPC
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC