THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vp52-pcj8-j9qc (high) — gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

[GHSA] GHSA-vp52-pcj8-j9qc (high) — gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

medgithub_advisoriesPublished 2026-09-01

GHSA-vp52-pcj8-j9qc Severity: high CVE: CVE-2026-84304

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

### Impact An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control win

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vp52-pcj8-j9qc