CVE-2026-84304
Reported by GitHub_M · Published September 1, 2026
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| grpc | grpc-go | < 1.83.1 |
| wolfi | datadog-agent-7.81 | 0, 0, 0 |
| chainguard | percona-xtradb-cluster-operator | 0, 0, 0 |
| chainguard | backup-restore-operator-fips-8.1 | 0, 0 |
| chainguard | aws-ebs-csi-driver-1.60 | 0, 0 |
| chainguard | cloud-provider-azure-1.34 | 0, 0 |
| chainguard | knative-kafka-broker-1.22 | 0, 0 |
| wolfi | cloud-sql-proxy-2.24 | 0, 0, 0 |
| chainguard | kubernetes-csi-external-resizer-fips | 0, 0, 0 |
| chainguard | gitlab-cng-19.2 | 0, 0 |
| wolfi | datadog-agent-7.77 | 0, 0 |
| chainguard | crossplane-provider-aws-ram-fips | 0, 0 |
| chainguard | tekton-pipelines-1.0 | 0, 0 |
| wolfi | scorecard | 0, 0, 0 |
| chainguard | grafana-mimir-fips-3.2 | 0, 0 |
| chainguard | velero-plugin-for-aws | 0, 0 |
| chainguard | dkron-fips | 0, 0 |
| chainguard | prometheus-fips-3.13 | 0, 0, 0 |
| wolfi | crossplane-provider-aws-cloudfront | 0, 0, 0 |
| wolfi | velero-plugin-for-aws | 0, 0, 0 |
…and 2386 more
Timeline
- Sep 1, 2026 CVE Published
- Sep 1, 2026 Coalition ESS Score
- Sep 1, 2026 CVE Updated
- Sep 2, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc x_refsource_CONFIRM
- https://github.com/grpc/grpc-go/pull/9331 x_refsource_MISC
- https://github.com/grpc/grpc-go/pull/9333 x_refsource_MISC
- https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176 x_refsource_MISC
- https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77 x_refsource_MISC
- https://github.com/grpc/grpc-go/releases/tag/v1.83.1 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-84304 advisory
- https://github.com/advisories/GHSA-vp52-pcj8-j9qc advisory