CVE-2026-84304: Uncontrolled Resource Consumption in gRPC-Go HTTP/2 Frame Processing
Vulnerability ID: CVE-2026-84304
CVSS Score: 8.7
Published: 2026-09-01
CVE-2026-84304 is a high-severity uncontrolled resource consumption vulnerability in gRPC-Go, the Go implementation of the gRPC framework. The issue stems from a memory amplification flaw inside the HTTP/2 DATA frame processing subsystem. Remote, unauthenticated attackers can exploit this vulnerability by sending a high volume of heavily fragmented, tiny DATA frames within multiplexed concurrent streams. This causes gRPC-Go servers to allocate excessive internal metadata structures on the Go heap, leading to severe heap memory amplification, intense garbage collection thrashing, and process termination due to Out-of-Memory (OOM) conditions.
TL;DR
An unauthenticated remote attacker can crash gRPC-Go servers (prior to version 1.83.1) by sending millions of fragmented, 1-byte HTTP/2 DATA frames. This bypasses standard flow control limits, forcing excessive metadata allocation on the heap and leading to Out-of-Memory (OOM) crashes.
Technical Details
- CWE ID: CWE-400
- Attack Vector: Network (AV:N)
- CVSS v4.0 Score: 8.7
- Vulnerability Type: Uncontrolled Resource Consumption
- Exploit Status: none
- CISA KEV Status: Not Listed
Affected Systems
- gRPC-Go applications utilizing transport layers prior to version 1.83.1.
-
gRPC-Go: < 1.83.1 (Fixed in:
1.83.1)
Code Analysis
Commit: 7354d9c
Implement receive buffer compaction to prevent heap memory exhaustion from tiny HTTP/2 frames.
Commit: 8cfeca0
Cherry-pick receive buffer compaction fixes to the v1.83.x release branch.
Mitigation Strategies
- Upgrade gRPC-Go library dependencies to version 1.83.1 or later.
- Enforce minimum HTTP/2 frame size limits via an edge proxy or WAF.
- Limit concurrent HTTP/2 streams per connection using gRPC server configuration parameters.
- Do not set GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION to false in production environments.
Remediation Steps:
- Open the project's go.mod file and locate the google.golang.org/grpc dependency.
- Run the command: go get google.golang.org/grpc@v1.83.1.
- Execute go mod tidy to update the dependency tree and verify the checksums in go.sum.
- Recompile all dependent application binaries and redeploy the updated services into production.
- Verify that the environment variable GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION is not disabled in the deployment templates.
References
- GitHub Security Advisory GHSA-vp52-pcj8-j9qc
- Fix Commit - Buffer Compaction Implementation
- Cherry-pick Commit to v1.83.x Release Branch
- gRPC-Go Pull Request #9331
- gRPC-Go Pull Request #9333
- gRPC-Go Release v1.83.1 Tag
Read the full report for CVE-2026-84304 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)