Description
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.
References (5)
Scores
CVSS v3
7.5
EPSS
0.0004
EPSS Percentile
12.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-248
Status
published
Products (4)
grpc/grpc
1.56.0
grpc/grpc
1.23.0 - 1.53.2
pypi/grpcio
1.55.0 - 1.55.3PyPI
rubygems/grpc
1.56.0 - 1.56.2RubyGems
Published
Sep 13, 2023
Tracked Since
Feb 18, 2026