grpc records
15 published records for vendor grpc.
Researcher profile
- Entered KEV
- 1 · 6.7%
- Weaponized
- 1 · 6.7%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-787 Out-of-bounds Write4
- CWE-440 Expected Behavior Violation3
- CWE-789 Memory Allocation with Excessive Size Value2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-285 Improper Authorization1
- CWE-617 Reachable Assertion1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
40Plan | CVE-2020-7768No exploit | The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.grpc · grpc · CWE-1321 | Critical9.8 | — | 4.2% | Nov 11, 2020 |
40Plan | CVE-2017-7860No exploit | Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/egrpc · grpc · CWE-787 | Critical9.8 | — | 3.1% | Apr 14, 2017 |
40Plan | CVE-2017-8359No exploit | Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in grpc · grpc · CWE-787 | Critical9.8 | — | 3.1% | Apr 30, 2017 |
40Plan | CVE-2017-7861No exploit | Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.grpc · grpc · CWE-787 | Critical9.8 | — | 2.9% | Apr 14, 2017 |
40Plan | CVE-2017-9431No exploit | Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.grpc · grpc · CWE-787 | Critical9.8 | — | 2.4% | Jun 4, 2017 |
36Monitor | CVE-2026-33186Proof of concept | gRPC-Go has an authorization bypass via missing leading slash in :pathgrpc · grpc · CWE-285 | Critical9.1 | — | 1.6% | Mar 20, 2026 |
30Monitor | CVE-2023-4785No exploit | Denial of Service in gRPC Coregrpc · grpc · CWE-248 | High7.5 | — | 0.8% | Sep 13, 2023 |
30Monitor | CVE-2023-32731No exploit | Information leak in gRPCgrpc · grpc · CWE-440 | High7.5 | — | 0.5% | Jun 9, 2023 |
30Monitor | CVE-2023-33953No exploit | Denial-of-Service in gRPCgrpc · grpc · CWE-789 | High7.5 | — | 0.5% | Aug 9, 2023 |
30Monitor | CVE-2023-1428No exploit | Denial-of-Service in gRPCgrpc · grpc · CWE-617 | High7.5 | — | 0.4% | Jun 9, 2023 |
27Monitor | CVE-2024-11407No exploit | Denial of Service through Data corruption in gRPC-C++grpc · grpc · CWE-682 | Medium6.9 | — | 0.6% | Nov 26, 2024 |
25Monitor | CVE-2024-7246No exploit | HPACK table poisoning in gRPC C++, Python & Rubygrpc · grpc · CWE-440 | Medium6.3 | — | 0.2% | Aug 6, 2024 |
21Monitor | CVE-2024-37168No exploit | @grpc/grpc-js can allocate memory for incoming messages well above configured limitsgrpc · grpc-node · CWE-789 | Medium5.3 | — | 0.7% | Jun 10, 2024 |
21Monitor | CVE-2023-32732No exploit | Denial-of-Service in gRPCgrpc · grpc · CWE-440 | Medium5.3 | — | 0.5% | Jun 9, 2023 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2020-776840Plan
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
CriticalCVSS 9.8No exploitEPSS 4%grpc · grpcNov 11, 2020
- CVE-2017-786040Plan
Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/e
CriticalCVSS 9.8No exploitEPSS 3%grpc · grpcApr 14, 2017
- CVE-2017-835940Plan
Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in
CriticalCVSS 9.8No exploitEPSS 3%grpc · grpcApr 30, 2017
- CVE-2017-786140Plan
Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.
CriticalCVSS 9.8No exploitEPSS 3%grpc · grpcApr 14, 2017
- CVE-2017-943140Plan
Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.
CriticalCVSS 9.8No exploitEPSS 2%grpc · grpcJun 4, 2017
- CVE-2026-3318636Monitor
gRPC-Go has an authorization bypass via missing leading slash in :path
CriticalCVSS 9.1Proof of conceptEPSS 2%grpc · grpcMar 20, 2026
- CVE-2023-478530Monitor
Denial of Service in gRPC Core
HighCVSS 7.5No exploitEPSS 1%grpc · grpcSep 13, 2023
- CVE-2023-3273130Monitor
Information leak in gRPC
HighCVSS 7.5No exploitEPSS 0%grpc · grpcJun 9, 2023
- CVE-2023-3395330Monitor
Denial-of-Service in gRPC
HighCVSS 7.5No exploitEPSS 0%grpc · grpcAug 9, 2023
- CVE-2023-142830Monitor
Denial-of-Service in gRPC
HighCVSS 7.5No exploitEPSS 0%grpc · grpcJun 9, 2023
- CVE-2024-1140727Monitor
Denial of Service through Data corruption in gRPC-C++
MediumCVSS 6.9No exploitEPSS 1%grpc · grpcNov 26, 2024
- CVE-2024-724625Monitor
HPACK table poisoning in gRPC C++, Python & Ruby
MediumCVSS 6.3No exploitEPSS 0%grpc · grpcAug 6, 2024
- CVE-2024-3716821Monitor
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
MediumCVSS 5.3No exploitEPSS 1%grpc · grpc-nodeJun 10, 2024
- CVE-2023-3273221Monitor
Denial-of-Service in gRPC
MediumCVSS 5.3No exploitEPSS 1%grpc · grpcJun 9, 2023