Allocation of Resources Without Limits or Throttling Affecting github.com/grpc/grpc-go/mem package, versions <1.83.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.42% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMGRPCGRPCGOMEM-19497926
  • published2 Sept 2026
  • disclosed1 Sept 2026
  • creditUnknown

Introduced: 1 Sep 2026

NewCVE-2026-84304  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade github.com/grpc/grpc-go/mem to version 1.83.1 or higher.

Overview

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the HTTP/2 DATA frame receive buffer handling, where each received fragment incurs per-fragment tracking and queue allocation overhead even while staying within the configured flow-control windows. An attacker can drive the process to an OutOfMemory condition or a runtime panic by opening gRPC streams and fragmenting payloads into millions of tiny HTTP/2 DATA frames, such as 1 byte each, across many concurrent multiplexed streams. This requires only the ability to establish gRPC stream connections to the server.

CVSS Base Scores

version 4.0
version 3.1