THREAT OPS › Threat News › [GHSA] GHSA-vp52-pcj8-j9qc (high) — gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
[GHSA] GHSA-vp52-pcj8-j9qc (high) — gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
GHSA-vp52-pcj8-j9qc Severity: high CVE: CVE-2026-84304
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
### Impact An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control win
Indicators of compromise
- CVE-2026-84304cve
Original source: https://github.com/advisories/GHSA-vp52-pcj8-j9qc