THREAT OPS › Threat News › [GHSA] GHSA-6ccx-9c9f-327w (high) — gRPC Erlang package has unbounded gzip decompression (decompression bomb)
[GHSA] GHSA-6ccx-9c9f-327w (high) — gRPC Erlang package has unbounded gzip decompression (decompression bomb)
GHSA-6ccx-9c9f-327w Severity: high CVE: CVE-2026-53430
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
### Summary An unauthenticated remote peer can crash any gRPC server built on this library by sending a small gzip-compressed frame that decompresses to gigabytes, exhausting the BEAM node's heap and triggering an OOM kill (denial of service).
Introduced in https://gi
Indicators of compromise
- beae6800fc8baf126f3fe7107d86a50e105275basha1
- CVE-2026-53430cve
Original source: https://github.com/advisories/GHSA-6ccx-9c9f-327w