Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Grpc

First CVE: Apr 14, 2017Active for: 9 yearsTotal CVEs: 14
73.7
VTI Score
TOP TARGET

gRPC is a widely embedded remote-procedure-call framework that, despite a focused product footprint, plays a critical role in microservices architectures and appears across numerous downstream applications and services. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability, alongside a recurring pattern of resource-exhaustion and memory-safety weaknesses characteristic of network-protocol parsers. Defenders should treat gRPC advisories as high-priority across their service infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 79% of tracked vendors
7.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Grpc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2017
9 years ago
Most Recent CVE
Mar 20, 2026
126 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2026-33186CRITICAL
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-heade
Mar 20, 20269.142NONO
CVE-2017-8359CRITICAL
Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c.
Apr 30, 20179.832NONO
CVE-2017-7860CRITICAL
Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.
Apr 14, 20179.832NONO
CVE-2020-7768CRITICAL
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
Nov 11, 20209.831NONO
CVE-2017-7861CRITICAL
Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.
Apr 14, 20179.831NONO
CVE-2017-9431CRITICAL
Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.
Jun 5, 20179.830NONO
CVE-2023-4785HIGH
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiat
Sep 13, 20237.523NONO
CVE-2023-33953HIGH
gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were foun
Aug 9, 20237.522NONO
CVE-2023-32731HIGH
When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a
Jun 9, 20237.522NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
14%
43%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
1 CVE
7.1% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Grpc.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Grpc — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Grpc's Products

View all 4 CNAs →

Top CWEs