CVE-2023-30637: Baidu Braft

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installations with brpc-0.14.0 and later are unaffected.

Affected products

  • Baidu Braft: version 1.1.2 only

Published 2023-04-13. Last modified 2026-06-17.