THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-grp7-v8xh-rj7h (critical) — gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads

[GHSA] GHSA-grp7-v8xh-rj7h (critical) — gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads

highgithub_advisoriesPublished 2026-08-25

GHSA-grp7-v8xh-rj7h Severity: critical CVE: CVE-2026-48853

gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads

### Summary

`GRPC.Codec.Erlpack.decode/2` calls `:erlang.binary_to_term/1` directly on the raw gRPC message body without the `:safe` option. Any unauthenticated peer that can reach a gRPC endpoint with `Content-Type: application/grpc+erlpack`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-grp7-v8xh-rj7h