VDB

CVE-2026-84304

CVE-2026-84304 PUBLISHED CVSS 8.7 HIGH

Reported by GitHub_M · Published September 1, 2026

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.

Risk Scores

CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
grpcgrpc-go< 1.83.1
wolfidatadog-agent-7.810, 0, 0
chainguardpercona-xtradb-cluster-operator0, 0, 0
chainguardbackup-restore-operator-fips-8.10, 0
chainguardaws-ebs-csi-driver-1.600, 0
chainguardcloud-provider-azure-1.340, 0
chainguardknative-kafka-broker-1.220, 0
wolficloud-sql-proxy-2.240, 0, 0
chainguardkubernetes-csi-external-resizer-fips0, 0, 0
chainguardgitlab-cng-19.20, 0
wolfidatadog-agent-7.770, 0
chainguardcrossplane-provider-aws-ram-fips0, 0
chainguardtekton-pipelines-1.00, 0
wolfiscorecard0, 0, 0
chainguardgrafana-mimir-fips-3.20, 0
chainguardvelero-plugin-for-aws0, 0
chainguarddkron-fips0, 0
chainguardprometheus-fips-3.130, 0, 0
wolficrossplane-provider-aws-cloudfront0, 0, 0
wolfivelero-plugin-for-aws0, 0, 0

…and 2386 more

Timeline

  • Sep 1, 2026 CVE Published
  • Sep 1, 2026 Coalition ESS Score
  • Sep 1, 2026 CVE Updated
  • Sep 2, 2026 EPSS Score
  • Sep 2, 2026 Security Advisory
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›