All 3 CVE vulnerabilities found in grpc-go, with AI-generated Chinese analysis, references, and POCs.
Vendor: grpc
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-84304 | gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation CWE-400 | 8.7 | High | 2026-09-01 |
| CVE-2026-84303 | gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion CWE-178 | 6.3 | Medium | 2026-09-01 |
| CVE-2026-33186 | gRPC-Go has an authorization bypass via missing leading slash in :path CWE-285 | 9.1 | Critical | 2026-03-20 |
All 3 known CVE vulnerabilities affecting grpc-go with full Chinese analysis, references, and POCs where available.