Known Vulnerabilities for products from Grpc
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Grpc".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34388 json | Not Provided | 2026-03-27 | 2026-03-31 | |
| CVE-2026-33783 json | Not Provided | 2026-04-09 | 2026-04-13 | |
| CVE-2026-33186 json | gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from impro... | Not Provided | 2026-03-20 | 2026-04-10 |
| CVE-2026-32811 json | Not Provided | 2026-03-20 | 2026-03-21 | |
| CVE-2026-5724 json | Not Provided | 2026-04-10 | 2026-04-10 | |
| CVE-2026-5536 json | Not Provided | 2026-04-05 | 2026-04-06 | |
| CVE-2023-44487 json | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many stre... | 7.5 - HIGH | 2023-10-10 | 2024-02-02 |
| CVE-2023-33953 json | gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients an... | 7.5 - HIGH | 2023-08-09 | 2023-08-17 |
| CVE-2023-32732 json | gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server:... | 5.3 - MEDIUM | 2023-06-09 | 2023-08-02 |
| CVE-2023-32731 json | When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HP... | 7.5 - HIGH | 2023-06-09 | 2023-06-15 |
| CVE-2023-4785 json | Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) all... | 7.5 - HIGH | 2023-09-13 | 2023-09-19 |
| CVE-2023-1428 json | There exists an vulnerability causing an abort() to be called in gRPC. The following headers cause gRPC's C++ implementatio... | 7.5 - HIGH | 2023-06-09 | 2023-06-15 |
| CVE-2020-7768 json | The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageD... | 9.8 - CRITICAL | 2020-11-11 | 2022-12-02 |
| CVE-2017-9431 json | Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/err... | 9.8 - CRITICAL | 2017-06-05 | 2017-06-12 |
| CVE-2017-8359 json | Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destr... | 9.8 - CRITICAL | 2017-04-30 | 2017-12-12 |
| CVE-2017-7861 json | Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c. | 9.8 - CRITICAL | 2017-04-14 | 2017-04-21 |
| CVE-2017-7860 json | Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix fun... | 9.8 - CRITICAL | 2017-04-14 | 2017-04-21 |
Known software with vulnerabilities from Grpc
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Grpc | Grpc | 0.10.0 |