Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
gRPC Erlang package has unbounded gzip decompression (decompression bomb) High
CVE-2026-53430 was published for grpc (Erlang) Aug 25, 2026
PJUllrich Credited to PJUllrich and polvalente polvalente polvalente
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3` High
CVE-2026-48854 was published for grpc (Erlang) Aug 25, 2026
PJUllrich Credited to PJUllrich, polvalente, and maennchen polvalente polvalente
maennchen maennchen
gRPC Erlang package's path bindings are overridable by query string and request body High
CVE-2026-48599 was published for grpc (Erlang) Aug 25, 2026
PJUllrich Credited to PJUllrich, polvalente, and maennchen polvalente polvalente
maennchen maennchen
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads Critical
CVE-2026-48853 was published for grpc (Erlang) Aug 25, 2026
PJUllrich Credited to PJUllrich, polvalente, and maennchen polvalente polvalente
maennchen maennchen
ProTip! Advisories are also available from the GraphQL API