google.golang.org/grpc
Activity
- Latest release
- Jun 08, 2026
- Total releases
- 50
- Cadence
- ~2 months
- Last 12 months
- 7
Details
- First release
- Dec 04, 2017
| Version | Released | |
|---|---|---|
v1.83.0-dev
pre
|
v1.83.0-dev
pre
Dependencies (22)
+ 14 more |
|
v1.80.0
minor
1 CVE
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev |
v1.80.0
minor
Dependencies (22)
+ 14 more |
|
v1.79.1
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.79.1
minor
Dependencies (22)
+ 14 more |
|
v1.78.0
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.78.0
minor
Dependencies (22)
+ 14 more |
|
v1.79.0-dev
pre
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.79.0-dev
pre
Dependencies (22)
+ 14 more |
|
v1.77.0-dev
pre
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.77.0-dev
pre
Dependencies (22)
+ 14 more |
|
v1.72.3
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.72.3
minor
Dependencies (21)
+ 13 more |
|
v1.71.3
patch
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.71.3
patch
Dependencies (20)
+ 12 more |
|
v1.71.2
patch
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.71.2
patch
Dependencies (20)
+ 12 more |
|
v1.71.1
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.71.1
minor
Dependencies (20)
+ 12 more |
|
v1.70.0
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.70.0
minor
Dependencies (19)
+ 11 more |
|
v1.71.0-dev
pre
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.71.0-dev
pre
Dependencies (19)
+ 11 more |
|
v1.68.2
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.68.2
minor
Dependencies (18)
+ 10 more |
|
v1.67.3
patch
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.67.3
patch
Dependencies (17)
+ 9 more |
|
v1.66.3
patch
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.66.3
patch
Dependencies (12)
+ 4 more |
|
v1.67.1
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.67.1
minor
Dependencies (12)
+ 4 more |
|
v1.66.1
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.66.1
minor
Dependencies (12)
+ 4 more |
|
v1.67.0-dev
pre
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.67.0-dev
pre
Dependencies (12)
+ 4 more |
|
v1.60.0
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.60.0
minor
Dependencies (14)
+ 6 more |
|
v1.56.3
minor
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.56.3
minor
Dependencies (13)
+ 5 more |
|
v1.58.3
patch
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.58.3
patch
Dependencies (14)
+ 6 more |
|
v1.58.1
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.58.1
minor
Dependencies (14)
+ 6 more |
|
v1.57.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.57.0
minor
Dependencies (14)
+ 6 more |
|
v1.55.1
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.55.1
minor
Dependencies (13)
+ 5 more |
|
v1.57.0-dev
pre
2 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev |
v1.57.0-dev
pre
Dependencies (13)
+ 5 more |
|
v1.54.1
patch
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.54.1
patch
Dependencies (13)
+ 5 more |
|
v1.54.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.54.0
minor
Dependencies (13)
+ 5 more |
|
v1.52.3
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.52.3
minor
Dependencies (13)
+ 5 more |
|
v1.53.0-dev
pre
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.53.0-dev
pre
Dependencies (13)
+ 5 more |
|
v1.49.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.49.0
minor
Dependencies (13)
+ 5 more |
|
v1.49.0-dev
pre
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.49.0-dev
pre
Dependencies (13)
+ 5 more |
|
v1.44.0-dev
pre
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.44.0-dev
pre
Dependencies (13)
+ 5 more |
|
v1.41.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.41.0
minor
Dependencies (12)
+ 4 more |
|
v1.40.0-dev
pre
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.40.0-dev
pre
Dependencies (11)
+ 3 more |
|
v1.34.2
patch
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.34.2
patch
Dependencies (11)
+ 3 more |
|
v1.37.0-dev
pre
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.37.0-dev
pre
Dependencies (11)
+ 3 more |
|
v1.34.1
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.34.1
minor
Dependencies (11)
+ 3 more |
|
v1.36.0-dev
pre
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.36.0-dev
pre
Dependencies (11)
+ 3 more |
|
v1.29.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.29.0
minor
Dependencies (10)
+ 2 more |
|
v1.29.0-dev
pre
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.29.0-dev
pre
Dependencies (10)
+ 2 more |
|
v1.28.0-pre
pre
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.28.0-pre
pre
Dependencies (10)
+ 2 more |
|
v1.26.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.26.0
minor
Dependencies (10)
+ 2 more |
|
v1.23.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.23.0
minor
Dependencies (12)
+ 4 more |
|
v1.21.3
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.21.3
minor
Dependencies (12)
+ 4 more |
|
v1.16.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.16.0
minor
Dependencies (11)
+ 3 more |
|
v1.15.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.15.0
minor
Dependencies (11)
+ 3 more |
|
v1.13.0
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.13.0
minor
|
|
v1.11.1
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.11.1
minor
|
|
v1.9.2
minor
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.9.2
minor
|
|
v1.7.4
initial
3 CVEs
GO-2026-6061
GHSA-hrxh-6v49-42gf
Jul 27, 2026
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc Fixed in
1.82.1
References Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-33186
GO-2026-4762
GHSA-p77j-4mvh-x3m3
Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc Fixed in
1.79.3
Updated Mar 30, 2026 · Source: OSV.dev
GO-2023-2153
GHSA-m425-mq94-257g
Nov 01, 2023
Denial of service from HTTP/2 Rapid Reset in google.golang.org/grpc An attacker can send HTTP/2 requests, cancel them, and send subsequent requests. This is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit, grpc.MaxConcurrentStreams. This results in a denial of service due to resource consumption. Fixed in
1.56.3
1.57.1
1.58.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.4
initial
|