Resource exhaustion in gRPC-go - #VU144260
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the HTTP/2 transport server implementation when handling rapid client-initiated stream creation and reset sequences. A remote attacker can send a rapid flood of HEADERS followed by RST_STREAM frames to cause a denial of service.
The condition bypasses the HTTP/2 Rapid Reset mitigation because queued control buffer items do not count against the transport response frame threshold, leading to high CPU consumption.
Affected software
Arista Streaming Telemetry Agent
Arista Extensible Operating System (EOS)
CloudVision Wi-Fi
Remediation
Arista Streaming Telemetry Agent - addressed in versions 1.31.17, 1.34.14, 1.37.13, 1.40.13, 1.43.8, 1.45.1, 1.46.0
Arista Extensible Operating System (EOS) - addressed in versions 4.33.9M, 4.34.8M, 4.35.6M, 4.36.2F
CloudVision Wi-Fi - update to 21.4.0M-12