Resource exhaustion in gRPC-go - CVE-2026-84304

 

Resource exhaustion in gRPC-go - CVE-2026-84304

Published: August 19, 2026 / Updated: September 2, 2026


Vulnerability identifier: #VU144264
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84304
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the HTTP/2 DATA frame handling logic when processing highly fragmented gRPC stream payloads. A remote attacker can send a large number of tiny HTTP/2 DATA frames across one or more streams to cause a denial of service.

The issue can exhaust heap memory and trigger a runtime panic or out-of-memory condition even when the total payload remains within configured connection and stream flow-control windows.


Affected software

gRPC-go
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Public Cloud Module
terraform-provider-null

How to mitigate CVE-2026-84304

Install security update from vendor's website.

gRPC-go - update to 1.83.1
terraform-provider-null - update to 3.0.0-150200.6.27.1

External References

Related Security Bulletins