grpc has 16 CVEs on record between 2023 and 2026. Disclosure cadence is accelerating: 9 in the last 90 days against 2 in the 90 before. The busiest recent month was August 2026 with 4. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-248 (4) and CWE-770 (3). Most affected products: grpc (6), google.golang.org/grpc (4), io.grpc:grpc-protobuf (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 9 prev 2
Products
- grpc 6
- google.golang.org/grpc 4
- io.grpc:grpc-protobuf 3
- @grpc/grpc-js 2
- grpc-go 1
Worst active — by depth score
CVE-2026-33186Critical· 9.1gRPC-Go is the Go language implementation of gRPC62CVE-2026-48853CriticalgRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads52CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC48CVE-2026-84304HighgRPC-Go is the Go language implementation of gRPC41CVE-2026-53430HighgRPC Erlang package has unbounded gzip decompression (decompression bomb)41
grpc vulnerabilities
CVEs affecting grpc, newest first. Open any entry for full detail, references, and exploit status.
16 CVEsRSS
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC
gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host heade…
CVE-2026-84303MediumgRPC-Go is the Go language implementation of gRPC
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are…
CVE-2026-84304HighgRPC-Go is the Go language implementation of gRPC
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate…
CVE-2026-48853CriticalgRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
CVE-2026-48599HighgRPC Erlang package's path bindings are overridable by query string and request body
gRPC Erlang package's path bindings are overridable by query string and request body
CVE-2026-48854HighgRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
CVE-2026-53430HighgRPC Erlang package has unbounded gzip decompression (decompression bomb)
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
GO-2026-6061NoneVulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
GHSA-hrxh-6v49-42gfHighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
CVE-2026-48069High· 7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-48068High· 7.5@grpc/grpc-js: A malformed request can cause a server crash
@grpc/grpc-js: A malformed request can cause a server crash
CVE-2026-33186Critical· 9.1PoCgRPC-Go is the Go language implementation of gRPC
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…
CVE-2023-4785High· 7.5Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
CVE-2023-32732Medium· 5.3gRPC connection termination issue
gRPC connection termination issue
CVE-2023-1428High· 7.5gRPC Reachable Assertion issue
gRPC Reachable Assertion issue
CVE-2023-32731High· 7.4Connection confusion in gRPC
Connection confusion in gRPC