google.golang.org/grpc
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting google.golang.org/grpcpage 1 of 1
- CVE-2026-33186CRITICALCVSS 9.1EG 9.1fixed in 1.79.32026-03-20
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic,…
- CVE-2026-84303MEDIUMCVSS 6.3EG 6.3fixed in 1.83.12026-09-01
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are l…
- CVE-2026-84304HIGHCVSS 8.7EG 8.7fixed in 1.83.12026-09-01
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate h…
- CVE-2026-84445HIGHCVSS 8.7EG 8.7fixed in 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3 or 1.85.0-dev.0.20260825072537-93e31b48545e, by version range2026-09-08
gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header,…
Check whether google.golang.org/grpc is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for google.golang.org/grpc CVEs against the assets you own.
Book a Demo →