CVE-2023-32732
MEDIUMgRPC < 1.53.0 - Denial of Service via Base64 Encoding Error in -bin Headers
Title source: llmDescription
gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309 https://www.google.com/url
References (3)
Core 3
Core References
Issue Tracking, Patch
https://github.com/grpc/grpc/pull/32309
Scores
CVSS v3
5.3
EPSS
0.0002
EPSS Percentile
7.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-440
Status
published
Products (6)
fedoraproject/fedora
37
fedoraproject/fedora
38
grpc/grpc
< 1.53.0
io.grpc/grpc-protobuf
1.53.0 - 1.53.1Maven
pypi/grpcio
1.53.0 - 1.53.1PyPI
rubygems/grpc
1.53.0 - 1.53.1RubyGems
Published
Jun 09, 2023
Tracked Since
Feb 18, 2026