MEDIUM 5.3 Maven

gRPC connection termination issue

GHSA-9hxf-ppjv-w6rq · CVE-2023-32732 · PYSEC-2026-1426

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for -bin suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309.

Ready to move

Start Securing

Free, no credit card | First findings in minutes