1sealsemantic last-mile verification

Research / Finding

gRPC-C++: enforce message size while decompressing

F-GRPC-001

Public snapshot: 7 Oct 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
GHSA-hf3w-6hpw-qp67GHSAgrpc/grpc

gRPC-C++: enforce message size while decompressing

Upstream fixed versions: github.com/grpc/grpc: 1.83.1 and 1.82.2

patched
details
Finding IDs
F-GRPC-001
GHSA
GHSA-hf3w-6hpw-qp67
Status
patched
Fixed in
gRPC 1.83.1 and 1.82.2; keep the default message_size_refactoring experiment enabled
Recorded credit
Public 1seal reporter credit and a causal link to the matching upstream fix are not established. Decompression patch author: Tanvi Jagtap.
Note
Only the unbounded-decompression cause matches F-GRPC-001; the advisory also covers two other OOM causes, which are not attributed to this report. The vendor rates the complete advisory HIGH and records no CVE or CVSS score. The earlier report attachment used a separate model, not a running gRPC server. The matching public patch bounds allocation during decompression; the fix is enabled by default and can be disabled via the message_size_refactoring experiment override.
Recorded severity
high
Upstream title
Multiple heap memory exhaustion (OOM) bug fixes in gRPC-C++
Upstream CWE
CWE-400
Upstream publication
Upstream updated
Metadata fetched
Upstream fixed versions
github.com/grpc/grpc: 1.83.1 and 1.82.2
Upstream affected ranges
github.com/grpc/grpc: <= 1.83.0
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

F-GRPC-001: Resource limits. Decompression can allocate beyond the configured maximum message length before rejecting the RPC. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.

Mechanism source for F-GRPC-001

Security area (1seal assessment): Availability. Decompression can allocate beyond the configured maximum message length before rejecting the RPC. Reviewed 7 Oct 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.