Known Vulnerabilities for Grpc-go by Grpc
Listed below are 10 of the newest known vulnerabilities associated with "Grpc-go" by "Grpc".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40969 json | The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC sta... | Not Provided | 2026-04-28 | 2026-04-28 |
| CVE-2026-40968 json | When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker t... | Not Provided | 2026-04-28 | 2026-04-28 |
| CVE-2026-40891 json | OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC using ... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-40182 json | OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-end/co... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-35579 json | CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations i... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-34388 json | Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher ... | Not Provided | 2026-03-27 | 2026-03-31 |
| CVE-2026-33783 json | A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PT... | Not Provided | 2026-04-09 | 2026-04-13 |
| CVE-2026-33190 json | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS tr... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-33186 json | gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from impro... | Not Provided | 2026-03-20 | 2026-03-24 |
| CVE-2026-32811 json | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decisi... | Not Provided | 2026-03-20 | 2026-03-21 |