All vulnerabilities
CVE-2023-4785
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
Description
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.
Patch Available
Fix available through Seal Security.
No upgrade required, protect your application instantly.
Fix without upgrading
Score
Severity
Ecosystem
Python
Publish Date
September 13, 2023
Modified Date
April 22, 2024
Score Vector
Affected Versions

