Skip to content
RequestGuard Vulnerabilities
Pricing

google.golang.org/grpc

Go package metadata, published advisories, affected versions, and known-exploitation evidence.

Go latest v1.84.0

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

v1.84.0

Published advisories match this version

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

7 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

7

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Affected range

SEMVER: introduced 0; fixed 1.82.2SEMVER: introduced 1.83.0; fixed 1.83.2SEMVER: introduced 1.84.0-dev; fixed 1.84.0-dev.0.20260825144003-d5a41119e0e3SEMVER: introduced 1.85.0-dev; fixed 1.85.0-dev.0.20260825072537-93e31b48545eSEMVER: introduced 0; fixed 1.82.2; introduced 1.83.0; fixed 1.83.2; introduced 1.84.0-dev; fixed 1.85.0-dev.0.20260825072537-93e31b48545e

Fixed versions: 1.82.2, 1.83.2, 1.84.0-dev.0.20260825144003-d5a41119e0e3, 1.85.0-dev.0.20260825072537-93e31b48545e

gRPC-Go HTTP/2 Rapid Reset vulnerability

Affected range

SEMVER: introduced 0; fixed 1.56.3SEMVER: introduced 1.57.0; fixed 1.57.1SEMVER: introduced 1.58.0; fixed 1.58.3SEMVER: introduced 0; fixed 1.56.3; introduced 1.57.0; fixed 1.57.1; introduced 1.58.0; fixed 1.58.3

Fixed versions: 1.56.3, 1.57.1, 1.58.3

Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go

Affected range

SEMVER: introduced 1.64.0; fixed 1.64.1

Fixed versions: 1.64.1