Known Vulnerabilities for products from Grpc

Listed below are 12 of the newest known vulnerabilities associated with the vendor "Grpc".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-34388 json Not Provided 2026-03-27 2026-03-31
CVE-2026-33783 json Not Provided 2026-04-09 2026-04-13
CVE-2026-33186 json gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from impro... Not Provided 2026-03-20 2026-04-10
CVE-2026-32811 json Not Provided 2026-03-20 2026-03-21
CVE-2026-5724 json Not Provided 2026-04-10 2026-04-10
CVE-2026-5536 json Not Provided 2026-04-05 2026-04-06
CVE-2023-44487 json The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many stre... 7.5 - HIGH 2023-10-10 2024-02-02
CVE-2023-33953 json gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients an... 7.5 - HIGH 2023-08-09 2023-08-17
CVE-2023-32732 json gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server:... 5.3 - MEDIUM 2023-06-09 2023-08-02
CVE-2023-32731 json When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HP... 7.5 - HIGH 2023-06-09 2023-06-15
CVE-2023-4785 json Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) all... 7.5 - HIGH 2023-09-13 2023-09-19
CVE-2023-1428 json There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementatio... 7.5 - HIGH 2023-06-09 2023-06-15
CVE-2020-7768 json The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageD... 9.8 - CRITICAL 2020-11-11 2022-12-02
CVE-2017-9431 json Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/err... 9.8 - CRITICAL 2017-06-05 2017-06-12
CVE-2017-8359 json Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destr... 9.8 - CRITICAL 2017-04-30 2017-12-12
CVE-2017-7861 json Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c. 9.8 - CRITICAL 2017-04-14 2017-04-21
CVE-2017-7860 json Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix fun... 9.8 - CRITICAL 2017-04-14 2017-04-21

Known software with vulnerabilities from Grpc

Type Vendor Product Version
ApplicationGrpcGrpc0.10.0