google.golang.org/grpc
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting google.golang.org/grpcpage 1 of 1
- CVE-2026-33186CRITICALCVSS 9.1EG 9.1✓ Fixed in 1.79.32026-03-20
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic,…
- CVE-2026-84303MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.83.12026-09-01
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are l…
- CVE-2026-84304HIGHCVSS 8.7EG 8.7✓ Fixed in 1.83.12026-09-01
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate h…
- CVE-2026-84445HIGHCVSS 8.7EG 8.7✓ Fixed in 1.85.0-dev.0.20260825072537-93e31b48545e2026-09-08
gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header,…
Check whether google.golang.org/grpc is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for google.golang.org/grpc CVEs against the assets you own.
Start Free Scan →