Description
In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). This is fixed in the 4.5.10 version. Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)
References (2)
Core 2
Core References
Issue Tracking
https://github.com/eclipse-vertx/vertx-grpc/issues/113
Issue Tracking, Vendor Advisory
https://gitlab.eclipse.org/security/cve-assignement/-/issues/31
Scores
CVSS v3
7.5
EPSS
0.0036
EPSS Percentile
58.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (3)
eclipse/vert.x
4.3.0 - 4.5.10
io.vertx/vertx-grpc-client
4.3.0 - 4.5.10Maven
io.vertx/vertx-grpc-server
4.3.0 - 4.5.10Maven
Published
Sep 04, 2024
Tracked Since
Feb 18, 2026