THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6ccx-9c9f-327w (high) — gRPC Erlang package has unbounded gzip decompression (decompression bomb)

[GHSA] GHSA-6ccx-9c9f-327w (high) — gRPC Erlang package has unbounded gzip decompression (decompression bomb)

highgithub_advisoriesPublished 2026-08-25

GHSA-6ccx-9c9f-327w Severity: high CVE: CVE-2026-53430

gRPC Erlang package has unbounded gzip decompression (decompression bomb)

### Summary An unauthenticated remote peer can crash any gRPC server built on this library by sending a small gzip-compressed frame that decompresses to gigabytes, exhausting the BEAM node's heap and triggering an OOM kill (denial of service).

Introduced in https://gi

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6ccx-9c9f-327w