Количество 16
Количество 16
CVE-2026-84304
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.
CVE-2026-84304
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.
CVE-2026-84304
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
CVE-2026-84304
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...
GHSA-vp52-pcj8-j9qc
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
BDU:2026-14130
Уязвимость файла internal/transport/transport.go фреймворка для удаленного вызова процедур на языке программирования Go gRPC-Go, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2026:4062-1
Security update for terraform-provider-null
openSUSE-SU-2026:21843-1
Security update for cadvisor
openSUSE-SU-2026:21834-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:4178-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:4125-1
Security update for azure-storage-azcopy
SUSE-SU-2026:4175-1
Security update for helm
openSUSE-SU-2026:21841-1
Security update for hauler
openSUSE-SU-2026:21809-1
Security update for helm
openSUSE-SU-2026:21801-1
Security update for trivy
openSUSE-SU-2026:21824-1
Security update for containerized-data-importer1.65
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-84304 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1. | 0% Низкий | 16 дней назад | ||
CVE-2026-84304 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1. | 0% Низкий | 16 дней назад | ||
CVE-2026-84304 gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | 0% Низкий | 12 дней назад | ||
CVE-2026-84304 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ... | 0% Низкий | 16 дней назад | ||
GHSA-vp52-pcj8-j9qc gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | 0% Низкий | 16 дней назад | ||
BDU:2026-14130 Уязвимость файла internal/transport/transport.go фреймворка для удаленного вызова процедур на языке программирования Go gRPC-Go, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | 30 дней назад | |
SUSE-SU-2026:4062-1 Security update for terraform-provider-null | 9 дней назад | |||
openSUSE-SU-2026:21843-1 Security update for cadvisor | 3 дня назад | |||
openSUSE-SU-2026:21834-1 Security update for google-cloud-sap-agent | 3 дня назад | |||
SUSE-SU-2026:4178-1 Security update for google-cloud-sap-agent | 3 дня назад | |||
SUSE-SU-2026:4125-1 Security update for azure-storage-azcopy | 6 дней назад | |||
SUSE-SU-2026:4175-1 Security update for helm | 3 дня назад | |||
openSUSE-SU-2026:21841-1 Security update for hauler | 3 дня назад | |||
openSUSE-SU-2026:21809-1 Security update for helm | 9 дней назад | |||
openSUSE-SU-2026:21801-1 Security update for trivy | 10 дней назад | |||
openSUSE-SU-2026:21824-1 Security update for containerized-data-importer1.65 | 8 дней назад |
Уязвимостей на страницу