gRPC is a widely embedded remote-procedure-call framework that, despite a focused product footprint, plays a critical role in microservices architectures and appears across numerous downstream applications and services. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability, alongside a recurring pattern of resource-exhaustion and memory-safety weaknesses characteristic of network-protocol parsers. Defenders should treat gRPC advisories as high-priority across their service infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Grpc over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2026-33186CRITICAL gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-heade | Mar 20, 2026 | 9.1 | 42 | NO | NO |
CVE-2017-8359CRITICAL Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c. | Apr 30, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-7860CRITICAL Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c. | Apr 14, 2017 | 9.8 | 32 | NO | NO |
CVE-2020-7768CRITICAL The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition. | Nov 11, 2020 | 9.8 | 31 | NO | NO |
CVE-2017-7861CRITICAL Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c. | Apr 14, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-9431CRITICAL Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c. | Jun 5, 2017 | 9.8 | 30 | NO | NO |
CVE-2023-4785HIGH Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiat | Sep 13, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-33953HIGH gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were foun | Aug 9, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-32731HIGH When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a | Jun 9, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Grpc.
Media articles that mention a CVE ID that affects a product developed by Grpc — matched by CVE ID, not by vendor name.