{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agooglegrpc-go/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:google:grpc-go:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-84304"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gRPC-Go (\u003c= 1.83.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Google"],"content_html":"\u003cp\u003eThe gRPC-Go library is susceptible to a remote Denial of Service (DoS) attack due to improper handling of HTTP/2 DATA frame fragmentation. By purposefully sending millions of tiny (e.g., 1-byte) HTTP/2 DATA frames within a gRPC stream, an attacker can bypass flow-control windows while inflating heap memory consumption. Each small frame incurs significant memory overhead caused by internal tracking structures and queue allocations within the gRPC-Go runtime.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this vulnerability by multiplexing multiple concurrent streams to rapidly exhaust the memory limits of the server. This memory exhaustion results in a runtime panic or an OutOfMemory (OOM) condition, rendering the service unresponsive. This vulnerability (CVE-2026-84304) affects all versions of google.golang.org/grpc up to and including 1.83.0. Defenders must prioritize upgrading to version 1.83.1, which introduces automatic receive buffer compaction to coalesce fragmented data frames and mitigate the overhead.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to an unauthenticated remote Denial of Service, causing application instability or complete service failure via OOM conditions. This impacts any infrastructure, microservice architecture, or external-facing API relying on vulnerable gRPC-Go implementations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade google.golang.org/grpc to version 1.83.1 or later to implement automatic receive buffer compaction.\u003c/li\u003e\n\u003cli\u003eAudit existing infrastructure to identify and patch dependencies using gRPC-Go versions \u0026lt;= 1.83.0.\u003c/li\u003e\n\u003cli\u003eDo not set the environment variable \u003ccode\u003eGRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false\u003c/code\u003e, as this disables the primary mitigation for this vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T00:00:00Z","date_published":"2026-09-02T00:00:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-grpc-go-dos/","summary":"An unauthenticated remote attacker can exploit HTTP/2 DATA frame fragmentation in gRPC-Go versions \u003c= 1.83.0 to cause heap memory exhaustion and application crashes.","title":"gRPC-Go Denial of Service via HTTP/2 Fragmentation","url":"https://feed.craftedsignal.io/briefs/2026-09-grpc-go-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:google:grpc-Go:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}