elixir-grpc gRPC Elixir是elixir-grpc组织的一款基于Elixir语言构建的gRPC框架。 elixir-grpc gRPC Elixir 0.4.0至1.0.0之前版本存在安全漏洞,该漏洞源于'Elixir.GRPC.Codec.Erlpack':decode/2函数在解码数据时未使用安全选项、无大小限制且无类型守卫,可能导致未经验证的攻击者利用特制有效载荷耗尽原子表或执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| elixir-grpc | grpc | 0.4.0< 1.0.0 |
affected |
25bcc569fe2cc4478531a6c546c923205fc751c9< 272a97a5ea1b46af1819f14a831fcf35fc91f992 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| elixir-grpc | grpc | 0.4.0 ~ 1.0.0 |
cpe:2.3:a:elixir-grpc:grpc:*:*:*:*:*:*:*:*
|
|
| elixir-grpc | grpc | 25bcc569fe2cc4478531a6c546c923205fc751c9 ~ 272a97a5ea1b46af1819f14a831fcf35fc91f992 |
cpe:2.3:a:elixir-grpc:grpc:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48854 | 8.7 HIGH | Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc |
| CVE-2026-48599 | 7.6 HIGH | Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding |
| CVE-2026-53430 | grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1 |
No comments yet