Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
High severity
GitHub Reviewed
Published
Sep 13, 2023
to the GitHub Advisory Database
•
Updated Apr 22, 2024
Description
Published by the National Vulnerability Database
Sep 13, 2023
Published to the GitHub Advisory Database
Sep 13, 2023
Reviewed
Feb 2, 2024
Last updated
Apr 22, 2024
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.
References