Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2026-84304

16 дней назад

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.

EPSS: Низкий
nvd логотип

CVE-2026-84304

16 дней назад

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.

EPSS: Низкий
msrc логотип

CVE-2026-84304

12 дней назад

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

EPSS: Низкий
debian логотип

CVE-2026-84304

16 дней назад

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...

EPSS: Низкий
github логотип

GHSA-vp52-pcj8-j9qc

16 дней назад

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

EPSS: Низкий
fstec логотип

BDU:2026-14130

30 дней назад

Уязвимость файла internal/transport/transport.go фреймворка для удаленного вызова процедур на языке программирования Go gRPC-Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4062-1

9 дней назад

Security update for terraform-provider-null

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21843-1

3 дня назад

Security update for cadvisor

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21834-1

3 дня назад

Security update for google-cloud-sap-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4178-1

3 дня назад

Security update for google-cloud-sap-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4125-1

6 дней назад

Security update for azure-storage-azcopy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4175-1

3 дня назад

Security update for helm

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21841-1

3 дня назад

Security update for hauler

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21809-1

9 дней назад

Security update for helm

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21801-1

10 дней назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21824-1

8 дней назад

Security update for containerized-data-importer1.65

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-84304

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.

0%
Низкий
16 дней назад
nvd логотип
CVE-2026-84304

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.

0%
Низкий
16 дней назад
msrc логотип
CVE-2026-84304

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

0%
Низкий
12 дней назад
debian логотип
CVE-2026-84304

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...

0%
Низкий
16 дней назад
github логотип
GHSA-vp52-pcj8-j9qc

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

0%
Низкий
16 дней назад
fstec логотип
BDU:2026-14130

Уязвимость файла internal/transport/transport.go фреймворка для удаленного вызова процедур на языке программирования Go gRPC-Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
30 дней назад
suse-cvrf логотип
SUSE-SU-2026:4062-1

Security update for terraform-provider-null

9 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21843-1

Security update for cadvisor

3 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21834-1

Security update for google-cloud-sap-agent

3 дня назад
suse-cvrf логотип
SUSE-SU-2026:4178-1

Security update for google-cloud-sap-agent

3 дня назад
suse-cvrf логотип
SUSE-SU-2026:4125-1

Security update for azure-storage-azcopy

6 дней назад
suse-cvrf логотип
SUSE-SU-2026:4175-1

Security update for helm

3 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21841-1

Security update for hauler

3 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21809-1

Security update for helm

9 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21801-1

Security update for trivy

10 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21824-1

Security update for containerized-data-importer1.65

8 дней назад

Уязвимостей на страницу