CVE-2023-4785: Grpc
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.
Affected products
- Grpc Grpc: from 1.23.0, before 1.53.2 (fixed in 1.53.2); from 1.54.0, before 1.54.3 (fixed in 1.54.3); from 1.55.0, before 1.55.3 (fixed in 1.55.3); version 1.56.0 only
Published 2023-09-13. Last modified 2026-06-17.