GHSA-m425-mq94-257g
ADVISORY - githubSummary
Impact
In affected releases of gRPC-Go, it is possible for an attacker to send HTTP/2 requests, cancel them, and send subsequent requests, which is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit.
Patches
This vulnerability was addressed by #6703 and has been included in patch releases: 1.56.3, 1.57.1, 1.58.3. It is also included in the latest release, 1.59.0.
Along with applying the patch, users should also ensure they are using the grpc.MaxConcurrentStreams
server option to apply a limit to the server's resources used for any single connection.
Workarounds
None.
References
#6703
Common Weakness Enumeration (CWE)
GitHub
3.9
CVSS SCORE
7.5highGoLang
-
Chainguard
CGA-2299-p283-6754
-
Chainguard
CGA-229m-7869-rw4v
-
Chainguard
CGA-24hx-83pv-289x
-
Chainguard
CGA-24wh-67j5-qfmx
-
Chainguard
CGA-2g34-888f-775q
-
Chainguard
CGA-2hxc-g6wm-jjjf
-
Chainguard
CGA-2pcr-mcjf-2wpx
-
Chainguard
CGA-2rv9-rcgf-5jmv
-
Chainguard
CGA-2v87-m46r-gjch
-
Chainguard
CGA-2v95-w62h-qj34
-
Chainguard
CGA-44rg-8c5h-mxm3
-
Chainguard
CGA-45mw-cxr8-gxqq
-
Chainguard
CGA-45r2-9m23-x9g6
-
Chainguard
CGA-4779-25p4-j7h2
-
Chainguard
CGA-4c3m-883j-8695
-
Chainguard
CGA-4fq8-xgh2-569j
-
Chainguard
CGA-4h3q-wr5r-mjhm
-
Chainguard
CGA-4mmr-qwxr-f88g
-
Chainguard
CGA-4rc6-3vhf-qf99
-
Chainguard
CGA-4vxm-hcpx-xxf3
-
Chainguard
CGA-5454-884w-3j88
-
Chainguard
CGA-54wm-9qp8-vc45
-
Chainguard
CGA-583h-35v8-3832
-
Chainguard
CGA-5cvg-3m7c-r33q
-
Chainguard
CGA-5jp5-95p2-jw83
-
Chainguard
CGA-5m9g-9jqg-pxgg
-
Chainguard
CGA-5q7j-fh45-2w4x
-
Chainguard
CGA-5v4r-558c-254r
-
Chainguard
CGA-6cxg-r834-pw8w
-
Chainguard
CGA-6mp3-8635-pxmr
-
Chainguard
CGA-6w85-h2rp-4xf2
-
Chainguard
CGA-6xf6-m4pj-ccc5
-
Chainguard
CGA-727j-3wf8-p4f6
-
Chainguard
CGA-75wc-3qwg-w6r6
-
Chainguard
CGA-765w-qmch-926x
-
Chainguard
CGA-7942-4mrf-v638
-
Chainguard
CGA-7vjh-3cq2-mm5j
-
Chainguard
CGA-824v-jhv4-f4mw
-
Chainguard
CGA-828f-q9xr-h575
-
Chainguard
CGA-87q9-5vhh-x7wh
-
Chainguard
CGA-8893-2h9f-wpwr
-
Chainguard
CGA-88pw-g8rx-54fw
-
Chainguard
CGA-8gmp-6559-9h7f
-
Chainguard
CGA-8mmc-vjfx-2x52
-
Chainguard
CGA-9653-v8w4-9j5m
-
Chainguard
CGA-99c5-2g66-4h88
-
Chainguard
CGA-9w4r-68hh-64j5
-
Chainguard
CGA-c3wx-3793-rqqm
-
Chainguard
CGA-c4h5-8qr7-cgwp
-
Chainguard
CGA-c8qm-548j-962c
-
Chainguard
CGA-cc75-jr7m-v4rg
-
Chainguard
CGA-cfmf-v2vf-446r
-
Chainguard
CGA-cq7q-jxpv-6fgm
-
Chainguard
CGA-cx34-c2p5-jvcw
-
Chainguard
CGA-cxhp-2cjv-664h
-
Chainguard
CGA-f4mx-67pf-r3qh
-
Chainguard
CGA-fvgh-72rr-6w75
-
Chainguard
CGA-fvvx-c3qf-g793
-
Chainguard
CGA-g5xx-v4jx-hxjh
-
Chainguard
CGA-gh3x-4cv3-3r74
-
Chainguard
CGA-gj4c-crx2-pm8v
-
Chainguard
CGA-gqv2-57jp-6hhp
-
Chainguard
CGA-gwxw-7hx6-fhc6
-
Chainguard
CGA-gxgw-6wgc-3c72
-
Chainguard
CGA-h3hf-wvxm-w8fq
-
Chainguard
CGA-h466-5h87-9xv8
-
Chainguard
CGA-hfrw-pwx5-923q
-
Chainguard
CGA-hwq5-r477-jpjj
-
Chainguard
CGA-j3qm-cjq5-x6cq
-
Chainguard
CGA-j67g-83pv-mx42
-
Chainguard
CGA-j72q-9qhf-w97c
-
Chainguard
CGA-j89h-cf4h-q65v
-
Chainguard
CGA-jchg-g7m5-gx9j
-
Chainguard
CGA-jfxc-mh76-f83w
-
Chainguard
CGA-jm66-m52h-37p8
-
Chainguard
CGA-jr4w-cr8g-qfvj
-
Chainguard
CGA-m2p9-447r-r54m
-
Chainguard
CGA-m49h-wjp5-j434
-
Chainguard
CGA-m96g-hjv2-7739
-
Chainguard
CGA-mp2h-9vj8-ph5p
-
Chainguard
CGA-mxmj-hx3p-86mr
-
Chainguard
CGA-p3wv-wqgx-5f9g
-
Chainguard
CGA-p7g8-rppq-492x
-
Chainguard
CGA-pj4x-489h-66rw
-
Chainguard
CGA-pm5v-cpg9-6pjv
-
Chainguard
CGA-pqvv-h3vv-2g39
-
Chainguard
CGA-pvf6-v7vv-5pm8
-
Chainguard
CGA-pwwr-2v47-j82m
-
Chainguard
CGA-q883-c6c7-5mrg
-
Chainguard
CGA-q8f4-cjcq-pvcw
-
Chainguard
CGA-qc4r-w3r7-vw5p
-
Chainguard
CGA-qg4w-crjp-pm66
-
Chainguard
CGA-qj23-2j5c-346p
-
Chainguard
CGA-qmv8-45h3-5mj9
-
Chainguard
CGA-qqq4-xppr-35gx
-
Chainguard
CGA-qw25-p74r-p556
-
Chainguard
CGA-r384-r6xg-gx77
-
Chainguard
CGA-r8fq-45qw-f82f
-
Chainguard
CGA-r9v9-3h8g-vvg8
-
Chainguard
CGA-rfpm-7c5c-2jr7
-
Chainguard
CGA-rwv7-vh72-vwm9
-
Chainguard
CGA-v87c-8cjq-58hx
-
Chainguard
CGA-v8m6-hgvj-q9jx
-
Chainguard
CGA-vf25-q86q-76h5
-
Chainguard
CGA-vhg8-353g-xgjq
-
Chainguard
CGA-w6jr-m8cm-cm2q
-
Chainguard
CGA-w8w4-2885-pj8c
-
Chainguard
CGA-w93r-jjhq-mrfj
-
Chainguard
CGA-w9wj-xx68-r8qj
-
Chainguard
CGA-wcvh-j92g-4jf2
-
Chainguard
CGA-wqph-8ch5-mjqf
-
Chainguard
CGA-wv77-q28p-3ccr
-
Chainguard
CGA-wvw7-cjc3-q29x
-
Chainguard
CGA-x3c3-mgmr-7hfc
-
Chainguard
CGA-x3gh-rmf6-3wm3
-
Chainguard
CGA-x6g2-mxqg-c3pc
-
Chainguard
CGA-x866-fvq6-vg5f
-
Chainguard
CGA-xfch-66rw-37j9
-
Chainguard
CGA-xghq-3xvr-mvcj
-
Chainguard
CGA-xp96-ggg6-9c44
-
Chainguard
CGA-xqpr-wh63-xxmp
-
Chainguard
CGA-xw4j-jwp2-3pcj
-