### ImpactThere are two separate code paths in which memory can be allocated per message in excess of the `grpc.max_receive_message_length` channel option: 1. If an incoming message has a size on the wire greater than the configured limit, the entire message is buffered before it is discarded. 2. If an incoming message has a size within the limit on the wire but decompresses to a size greater than the limit, the entire message is decompressed into memory, and on the server is not discarded.### PatchesThis has been patched in versions 1.10.9, 1.9.15, and 1.8.22
Fix available through Seal Security. No upgrade required, protect your application instantly.
Fix without upgrading