Resource exhaustion in gRPC-go - CVE-2026-84304
Published: August 19, 2026 / Updated: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the HTTP/2 DATA frame handling logic when processing highly fragmented gRPC stream payloads. A remote attacker can send a large number of tiny HTTP/2 DATA frames across one or more streams to cause a denial of service.
The issue can exhaust heap memory and trigger a runtime panic or out-of-memory condition even when the total payload remains within configured connection and stream flow-control windows.
Affected software
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Public Cloud Module
terraform-provider-null
How to mitigate CVE-2026-84304
terraform-provider-null - update to 3.0.0-150200.6.27.1