highVulnerability

CVE-2026-84304

### Impact An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control windows, each independent fragment incurs memory overhead due to internal tracking structures and queue allocation. Repeated fragmentation massively inflates the heap space consumed by the stream. An attacker multiplexing multiple concurrent streams can exhaust the memory bounds of the runtime, forcing a runtime panic or OutOfMemory condition and leading to a remote Denial of Service (DoS). ### Patches The change to fix this issue is merged in `master` and a patch release, 1.83.1, has been published that contains this fix. ### Workarounds This vulnerability is mitigated by implementing receive buffer compaction. Consecutive small data buffers are automatically coalesced into larger buffers from a shared pool once the overhead is perceived to be excessive relative to actual payload data, drastically minimizing per-frame memory overheads. This behavior is enabled by default. A temporary escape hatch is provided via the environment variable `GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false` to disable the feature if unforeseen issues arise, but it will be removed in a future release.

Properties

ghsa_id
GHSA-vp52-pcj8-j9qc
severity
high
summary
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
cve_id
CVE-2026-84304
is_ghsa_only
false
ghsa_published
2026-09-01T21:32:41Z
source_url
https://github.com/advisories/GHSA-vp52-pcj8-j9qc
ghsa_updated
2026-09-01T21:32:45Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/google.golang.org/grpc

AFFECTS (1)

[Software]go/google.golang.org/grpc

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84304 — Ninja Signal Threat Intelligence | Ninja Signal