VulnSea

grpc has 16 CVEs on record between 2023 and 2026. Disclosure cadence is accelerating: 9 in the last 90 days against 2 in the 90 before. The busiest recent month was August 2026 with 4. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-248 (4) and CWE-770 (3). Most affected products: grpc (6), google.golang.org/grpc (4), io.grpc:grpc-protobuf (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
9 prev 2

Products

  • grpc 6
  • google.golang.org/grpc 4
  • io.grpc:grpc-protobuf 3
  • @grpc/grpc-js 2
  • grpc-go 1
16
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

grpc vulnerabilities

CVEs affecting grpc, newest first. Open any entry for full detail, references, and exploit status.

16 CVEsRSS

CVE-2026-84445High· 8.7
1w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host heade…

Twilightgrpc · grpc-goEPSS 0.69%via NVD
CVE-2026-84303Medium
2w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are…

Sunlitgrpc · google.golang.org/grpcEPSS 0.31%via NVD
CVE-2026-84304High
2w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate…

Twilightgrpc · google.golang.org/grpcEPSS 0.41%via NVD
CVE-2026-48853Critical
3w ago

gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads

gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads

Midnightgrpc · grpcEPSS 0.57%via GHSA
CVE-2026-48599High
3w ago

gRPC Erlang package's path bindings are overridable by query string and request body

gRPC Erlang package's path bindings are overridable by query string and request body

Twilightgrpc · grpcEPSS 0.27%via GHSA
CVE-2026-48854High
3w ago

gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`

gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`

Twilightgrpc · grpcEPSS 0.34%via GHSA
CVE-2026-53430High
3w ago

gRPC Erlang package has unbounded gzip decompression (decompression bomb)

gRPC Erlang package has unbounded gzip decompression (decompression bomb)

Twilightgrpc · grpcEPSS 0.35%via GHSA
GO-2026-6061None
1mo ago

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

Sunlitgrpc · google.golang.org/grpcvia OSV
GHSA-hrxh-6v49-42gfHigh
2mo ago

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

Twilightgrpc · google.golang.org/grpcvia GHSA
CVE-2026-48069High· 7.5
3mo ago

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

Twilightgrpc · @grpc/grpc-jsEPSS 0.88%via GHSA
CVE-2026-48068High· 7.5
3mo ago

@grpc/grpc-js: A malformed request can cause a server crash

@grpc/grpc-js: A malformed request can cause a server crash

Twilightgrpc · @grpc/grpc-jsEPSS 0.62%via GHSA
CVE-2026-33186Critical· 9.1PoC
6mo ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…

Abyssalgrpc · grpcEPSS 1.6%via NVD
CVE-2023-4785High· 7.5
3y ago

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Twilightgrpc · grpcEPSS 0.77%via OSV
CVE-2023-32732Medium· 5.3
3y ago

gRPC connection termination issue

gRPC connection termination issue

Sunlitgrpc · io.grpc:grpc-protobufEPSS 0.53%via OSV
CVE-2023-1428High· 7.5
3y ago

gRPC Reachable Assertion issue

gRPC Reachable Assertion issue

Twilightgrpc · io.grpc:grpc-protobufEPSS 0.41%via OSV
CVE-2023-32731High· 7.4
3y ago

Connection confusion in gRPC

Connection confusion in gRPC

Twilightgrpc · io.grpc:grpc-protobufEPSS 0.50%via OSV
grpc vulnerabilities (CVEs) · VulnSea