gRPC-C++: enforce message size while decompressing
Upstream fixed versions: github.com/grpc/grpc: 1.83.1 and 1.82.2
details
- Finding IDs
- F-GRPC-001
- GHSA
- GHSA-hf3w-6hpw-qp67
- Status
- patched
- Fixed in
- gRPC 1.83.1 and 1.82.2; keep the default message_size_refactoring experiment enabled
- Recorded credit
- Public 1seal reporter credit and a causal link to the matching upstream fix are not established. Decompression patch author: Tanvi Jagtap.
- Note
- Only the unbounded-decompression cause matches F-GRPC-001; the advisory also covers two other OOM causes, which are not attributed to this report. The vendor rates the complete advisory HIGH and records no CVE or CVSS score. The earlier report attachment used a separate model, not a running gRPC server. The matching public patch bounds allocation during decompression; the fix is enabled by default and can be disabled via the message_size_refactoring experiment override.
- Recorded severity
- high
- Upstream title
- Multiple heap memory exhaustion (OOM) bug fixes in gRPC-C++
- Upstream CWE
- CWE-400
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream fixed versions
- github.com/grpc/grpc: 1.83.1 and 1.82.2
- Upstream affected ranges
- github.com/grpc/grpc: <= 1.83.0
- Upstream @1seal credit
- No structured @1seal credit in this snapshot; textual acknowledgements may exist.
F-GRPC-001: Resource limits. Decompression can allocate beyond the configured maximum message length before rejecting the RPC. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-GRPC-001
Security area (1seal assessment): Availability. Decompression can allocate beyond the configured maximum message length before rejecting the RPC. Reviewed 7 Oct 2026.