CVE-2021-36155

HIGH

gRPC Swift <= 1.1.0 - Denial of Service via LengthPrefixedMessageReader

Title source: llm
STIX 2.1

Description

LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.

References (3)

Core 3
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/grpc/grpc-swift/releases
Mailing List, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=35303

Scores

CVSS v3 7.5
EPSS 0.0085
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (4)
linuxfoundation/grpc_swift 1.0.0
linuxfoundation/grpc_swift 1.1.0
linuxfoundation/grpc_swift 1.1.1
SwiftURL/github.com/grpc/grpc-swift 0 - 1.2.0SwiftURL
Published Jul 09, 2021
Tracked Since Feb 18, 2026