THREAT OPS › Threat News › [GHSA] GHSA-grp7-v8xh-rj7h (critical) — gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
[GHSA] GHSA-grp7-v8xh-rj7h (critical) — gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
GHSA-grp7-v8xh-rj7h Severity: critical CVE: CVE-2026-48853
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
### Summary
`GRPC.Codec.Erlpack.decode/2` calls `:erlang.binary_to_term/1` directly on the raw gRPC message body without the `:safe` option. Any unauthenticated peer that can reach a gRPC endpoint with `Content-Type: application/grpc+erlpack`
Indicators of compromise
- 25bcc569fe2cc4478531a6c546c923205fc751c9sha1
- 272a97a5ea1b46af1819f14a831fcf35fc91f992sha1
- CVE-2026-48853cve
Original source: https://github.com/advisories/GHSA-grp7-v8xh-rj7h