{"id":"GHSA-m425-mq94-257g","aliases":["GO-2023-2153"],"url":"https://o3.security/vulnerability/GHSA-m425-mq94-257g","summary":"gRPC-Go HTTP/2 Rapid Reset vulnerability","details":"### Impact\nIn affected releases of gRPC-Go, it is possible for an attacker to send HTTP/2 requests, cancel them, and send subsequent requests, which is valid by the HTTP/2 protocol, but would cause the gRPC-Go server to launch more concurrent method handlers than the configured maximum stream limit.\n\n### Patches\nThis vulnerability was addressed by #6703 and has been included in patch releases: 1.56.3, 1.57.1, 1.58.3.  It is also included in the latest release, 1.59.0.\n\nAlong with applying the patch, users should also ensure they are using the `grpc.MaxConcurrentStreams` server option to apply a limit to the server's resources used for any single connection.\n\n### Workarounds\nNone.\n\n### References\n#6703\n","published":"2023-10-25T21:17:37Z","modified":"2026-09-10T03:49:58.618819673Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"google.golang.org/grpc","fixedVersion":"1.56.3"},{"ecosystem":"Go","name":"google.golang.org/grpc","fixedVersion":"1.57.1"},{"ecosystem":"Go","name":"google.golang.org/grpc","fixedVersion":"1.58.3"}],"fix":{"url":"https://github.com/grpc/grpc-go/pull/6703","label":"grpc/grpc-go#6703"},"references":[{"type":"WEB","url":"https://github.com/grpc/grpc-go/security/advisories/GHSA-m425-mq94-257g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-44487"},{"type":"WEB","url":"https://github.com/grpc/grpc-go/pull/6703"},{"type":"WEB","url":"https://github.com/grpc/grpc-go/commit/f2180b4d5403d2210b30b93098eb7da31c05c721"},{"type":"PACKAGE","url":"https://github.com/grpc/grpc-go"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:49:58.618819673Z"}}