Skip to content

[🐸 Frogbot] Update version of google.golang.org/grpc to 1.84.0-dev.0.20260911104110-c5ae88df420f - #1442

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
frogbot-google.golang.org/grpc-df13611d822eb1da65f4ec94eca6f291
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
frogbot-google.golang.org/grpc-df13611d822eb1da65f4ec94eca6f291

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🚨 This automated pull request was created by Frogbot and fixes the below:

📦 Vulnerable Dependencies

Severity ID Contextual Analysis Dependency Path
high
High
CVE-2026-84304 Not Covered
1 Directgoogle.golang.org/grpc:1.79.3
1 Transitivegoogle.golang.org/grpc:1.79.3

🔖 Details

Vulnerability Details

Contextual Analysis: Not Covered
CVSS V3: -
Dependency Path:
google.golang.org/grpc: 1.79.3 (Transitive)Fix Version: 1.84.0-dev.0.20260911104110-c5ae88df420f

Impact

An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control windows, each independent fragment incurs memory overhead due to internal tracking structures and queue allocation.

Repeated fragmentation massively inflates the heap space consumed by the stream. An attacker multiplexing multiple concurrent streams can exhaust the memory bounds of the runtime, forcing a runtime panic or OutOfMemory condition and leading to a remote Denial of Service (DoS).

Patches

The change to fix this issue is merged in master and a patch release, 1.83.1, has been published that contains this fix.

Workarounds

This vulnerability is mitigated by implementing receive buffer compaction. Consecutive small data buffers are automatically coalesced into larger buffers from a shared pool once the overhead is perceived to be excessive relative to actual payload data, drastically minimizing per-frame memory overheads.

This behavior is enabled by default. A temporary escape hatch is provided via the environment variable GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false to disable the feature if unforeseen issues arise, but it will be removed in a future release.


@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 344f30f2-4705-4ec0-aad0-a41412e927ad

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant