Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2210588
AlmaLinux
5931
Alpaquita
16087
Alpine
4608
Android
3677
Azure Linux
17651
BellSoft Hardened Containers
754
Bitnami
9325
Chainguard
1030811
CleanStart
3846
CRAN
14
crates.io
2739
Debian
68551
Echo
7457
GHC
3
GIT
108258
GitHub Actions
55
Go
9245
Hackage
33
Hex
364
Julia
1713
Linux
29974
Mageia
6232
Maven
7044
MinimOS
145008
npm
228862
NuGet
1869
opam
29
openEuler
8800
openSUSE
14480
OSS-Fuzz
4013
Packagist
7098
Pub
11
PyPI
25183
Red Hat
23387
Rocky Linux
4305
Root
19581
RubyGems
5326
SUSE
23350
SwiftURL
60
TuxCare
9606
Ubuntu
65406
VSCode
21
Wolfi
289821
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-84445
github.com/grpc/grpc-go
gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers in the xDS servers
14 Sep
Fix available
Severity - 8.7 (High)
CVE-2026-84304
github.com/grpc/grpc-go
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
01 Sep
Fix available
Severity - 8.7 (High)
CVE-2026-84303
github.com/grpc/grpc-go
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
01 Sep
Fix available
Severity - 6.3 (Medium)
CVE-2026-33186
github.com/grpc/grpc-go
gRPC-Go has an authorization bypass via missing leading slash in :path
20 Mar
Fix available
Severity - 9.1 (Critical)
CVE-2024-11407
github.com/grpc/grpc
github.com/grpc/grpc-go
Denial of Service through Data corruption in gRPC-C++
26 Nov 2024
Fix available
Severity - 6.9 (Medium)
CVE-2024-7246
github.com/grpc/grpc
github.com/grpc/grpc-go
github.com/grpc/grpc-java
HPACK table poisoning in gRPC C++, Python & Ruby
06 Aug 2024
Fix available
Severity - 6.3 (Medium)
CVE-2023-44487
github.com/akka/akka-http
github.com/alibaba/tengine
github.com/apache/httpd
github.com/apache/solr
github.com/apache/tomcat
... 33 more
See record for full details
10 Oct 2023
Fix available
Severity - 7.5 (High)
CVE-2023-4785
github.com/grpc/grpc
github.com/grpc/grpc-go
github.com/grpc/grpc-java
Denial of Service in gRPC Core
13 Sep 2023
Fix available
Severity - 7.5 (High)
CVE-2023-33953
github.com/grpc/grpc
github.com/grpc/grpc-go
Denial-of-Service in gRPC
09 Aug 2023
Fix available
Severity - 7.5 (High)
CVE-2023-32731
github.com/grpc/grpc
github.com/grpc/grpc-go
github.com/grpc/grpc-java
Information leak in gRPC
09 Jun 2023
Fix available
Severity - 7.4 (High)
CVE-2023-32732
github.com/grpc/grpc
github.com/grpc/grpc-go
github.com/grpc/grpc-java
Denial-of-Service in gRPC
09 Jun 2023
Fix available
Severity - 5.3 (Medium)
CVE-2023-1428
github.com/grpc/grpc
github.com/grpc/grpc-go
github.com/grpc/grpc-java
Denial-of-Service in gRPC
09 Jun 2023
Fix available
Severity - 7.5 (High)
CVE-2017-8359
github.com/grpc/grpc
github.com/grpc/grpc-go
github.com/grpc/grpc-kotlin
github.com/grpc/grpc-node
github.com/grpc/grpc-web
See record for full details
30 Apr 2017
No fix available
Severity - 9.8 (Critical)
Vulnerability Database - OSV