{"id":"GHSA-xr7q-jx4m-x55m","aliases":["GO-2024-2978"],"url":"https://o3.security/vulnerability/GHSA-xr7q-jx4m-x55m","summary":"Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go","details":"### Impact\nThis issue represents a potential PII concern.  If applications were printing or logging a context containing gRPC metadata, the affected versions will contain all the metadata, which may include private information.\n\n### Patches\nThe issue first appeared in 1.64.0 and is patched in 1.64.1 and 1.65.0\n\n### Workarounds\nIf using an affected version and upgrading is not possible, ensuring you do not log or print contexts will avoid the problem.\n","published":"2024-07-05T20:07:01Z","modified":"2026-09-10T03:50:17.144982671Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"google.golang.org/grpc","fixedVersion":"1.64.1"}],"fix":{"url":"https://github.com/grpc/grpc-go/commit/ab292411ddc0f3b7a7786754d1fe05264c3021eb","label":"grpc/grpc-go@ab29241"},"references":[{"type":"WEB","url":"https://github.com/grpc/grpc-go/security/advisories/GHSA-xr7q-jx4m-x55m"},{"type":"WEB","url":"https://github.com/grpc/grpc-go/commit/ab292411ddc0f3b7a7786754d1fe05264c3021eb"},{"type":"PACKAGE","url":"https://github.com/grpc/grpc-go"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:17.144982671Z"}}