Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-48853— Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc

Quick assessment

Affected
elixir-grpc grpc
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

elixir-grpc gRPC Elixir是elixir-grpc组织的一款基于Elixir语言构建的gRPC框架。 elixir-grpc gRPC Elixir 0.4.0至1.0.0之前版本存在安全漏洞,该漏洞源于'Elixir.GRPC.Codec.Erlpack':decode/2函数在解码数据时未使用安全选项、无大小限制且无类型守卫,可能导致未经验证的攻击者利用特制有效载荷耗尽原子表或执行任意代码。

CVSS 9.2 · Critical EPSS 0.78% · P55

Affected Version Matrix 2

VendorProduct Version RangeStatus
elixir-grpc grpc 0.4.0< 1.0.0 affected
25bcc569fe2cc4478531a6c546c923205fc751c9< 272a97a5ea1b46af1819f14a831fcf35fc91f992 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-48853

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc
Source: CVE Program / CVE List V5
Vulnerability Description
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server. 'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process. This issue affects grpc: from 0.4.0 before 1.0.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5
Vulnerability Title
elixir-grpc gRPC Elixir 反序列化漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
elixir-grpc gRPC Elixir是elixir-grpc组织的一款基于Elixir语言构建的gRPC框架。 elixir-grpc gRPC Elixir 0.4.0至1.0.0之前版本存在安全漏洞,该漏洞源于'Elixir.GRPC.Codec.Erlpack':decode/2函数在解码数据时未使用安全选项、无大小限制且无类型守卫,可能导致未经验证的攻击者利用特制有效载荷耗尽原子表或执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
elixir-grpc grpc 0.4.0 ~ 1.0.0 cpe:2.3:a:elixir-grpc:grpc:*:*:*:*:*:*:*:*
elixir-grpc grpc 25bcc569fe2cc4478531a6c546c923205fc751c9 ~ 272a97a5ea1b46af1819f14a831fcf35fc91f992 cpe:2.3:a:elixir-grpc:grpc:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-48853

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-48853

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-48853 (1)

Vendor Advisories for CVE-2026-48853 (3)

Same Patch Batch · elixir-grpc · 2026-06-15 · 4 CVEs total

CVE-2026-48854 8.7 HIGH Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc
CVE-2026-48599 7.6 HIGH Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding
CVE-2026-53430 grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1

IV. Related Vulnerabilities

V. Comments for CVE-2026-48853

No comments yet


Leave a comment