<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:56:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-08312</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-08312</link>
      <description>bdu:2026-08312</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-08312</guid>
    </item>
    <item>
      <title>EUVD-2026-327858</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-327858</link>
      <description>EUVD-2026-327858</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-327858</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53430</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53430</link>
      <description>&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/message.ex and program routines &amp;#39;Elixir.GRPC.Compressor.Gzip&amp;#39;:decompress/1, &amp;#39;Elixir.GRPC.Message&amp;#39;:from_data/2.&lt;/p&gt;
&lt;p&gt;&amp;#39;Elixir.GRPC.Compressor.Gzip&amp;#39;:decompress/1 calls :zlib.gunzip/1 directly on attacker-controlled bytes with no decompressed-size limit, ratio check, or incremental decoding. Because this module is the registered gzip GRPC.Compressor implementation, it is invoked automatically whenever an incoming gRPC frame carries the grpc-encoding: gzip header. :zlib.gunzip/1 allocates the entire decompressed result as a single binary, so a small highly compressible payload (for example a few kilobytes of zeros, which gzip compresses at roughly 1000:1) expands to multiple gigabytes inside a single call. The max_receive_message_length limit is enforced only against the already-decompressed message, so it provides no protection. An unauthenticated remote peer can send a single crafted frame to exhaust the BEAM node&amp;#39;s heap and trigger an out-of-memory kill.&lt;/p&gt;
&lt;p&gt;This issue affects grpc: from 0.4.0 before 1.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/message.ex and program routines &amp;#39;Elixir.GRPC.Compressor.Gzip&amp;#39;:decompress/1, &amp;#39;Elixir.GRPC.Message&amp;#39;:from_data/2.&lt;/p&gt;
&lt;p&gt;&amp;#39;Elixir.GRPC.Compressor.Gzip&amp;#39;:decompress/1 calls :zlib.gunzip/1 directly on attacker-controlled bytes with no decompressed-size limit, ratio check, or incremental decoding. Because this module is the registered gzip GRPC.Compressor implementation, it is invoked automatically whenever an incoming gRPC frame carries the grpc-encoding: gzip header. :zlib.gunzip/1 allocates the entire decompressed result as a single binary, so a small highly compressible payload (for example a few kilobytes of zeros, which gzip compresses at roughly 1000:1) expands to multiple gigabytes inside a single call. The max_receive_message_length limit is enforced only against the already-decompressed message, so it provides no protection. An unauthenticated remote peer can send a single crafted frame to exhaust the BEAM node&amp;#39;s heap and trigger an out-of-memory kill.&lt;/p&gt;
&lt;p&gt;This issue affects grpc: from 0.4.0 before 1.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53430</guid>
    </item>
    <item>
      <title>GHSA-6ccx-9c9f-327w — gRPC Erlang package has unbounded gzip decompression (decompression bomb)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6ccx-9c9f-327w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: grpc&lt;/p&gt;
&lt;p&gt;### Summary
An unauthenticated remote peer can crash any gRPC server built on this library by sending a small gzip-compressed frame that decompresses to gigabytes, exhausting the BEAM node&amp;#39;s heap and triggering an OOM kill (denial of service).&lt;/p&gt;
&lt;p&gt;Introduced in https://github.com/elixir-grpc/grpc/commit/beae6800fc8baf126f3fe7107d86a50e105275ba&lt;/p&gt;
&lt;p&gt;### Details
`GRPC.Compressor.Gzip.decompress/1` (lib/grpc/compressor/gzip.ex:12-14) calls `:zlib.gunzip/1` directly on attacker-controlled bytes with no size limit, no ratio check, and no incremental decoding. Because this module is registered as a `GRPC.Compressor` implementation, it is invoked automatically whenever an incoming gRPC frame carries `grpc-encoding: gzip`. `:zlib.gunzip/1` allocates the entire decompressed result as a single binary before returning, so a highly compressible payload (e.g. a few kilobytes of zeros, which gzip compresses at roughly 1000:1) expands to multiple gigabytes inside a single function call. The server&amp;#39;s `max_receive_message_length` is enforced only against the already-decompressed message, so it provides no protection here. A single request is sufficient to OOM-kill the node.&lt;/p&gt;
&lt;p&gt;### PoC
A script that verifies the vulnerability is attached to the end of this report. Run it against a stock gRPC server using this library; the BEAM node&amp;#39;s memory usage will balloon and the VM will be OOM-killed after a single request.&lt;/p&gt;
&lt;p&gt;### Impact
This is a decompression bomb / denial-of-service vulnerability. Any service th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: grpc&lt;/p&gt;
&lt;p&gt;### Summary
An unauthenticated remote peer can crash any gRPC server built on this library by sending a small gzip-compressed frame that decompresses to gigabytes, exhausting the BEAM node&amp;#39;s heap and triggering an OOM kill (denial of service).&lt;/p&gt;
&lt;p&gt;Introduced in https://github.com/elixir-grpc/grpc/commit/beae6800fc8baf126f3fe7107d86a50e105275ba&lt;/p&gt;
&lt;p&gt;### Details
`GRPC.Compressor.Gzip.decompress/1` (lib/grpc/compressor/gzip.ex:12-14) calls `:zlib.gunzip/1` directly on attacker-controlled bytes with no size limit, no ratio check, and no incremental decoding. Because this module is registered as a `GRPC.Compressor` implementation, it is invoked automatically whenever an incoming gRPC frame carries `grpc-encoding: gzip`. `:zlib.gunzip/1` allocates the entire decompressed result as a single binary before returning, so a highly compressible payload (e.g. a few kilobytes of zeros, which gzip compresses at roughly 1000:1) expands to multiple gigabytes inside a single function call. The server&amp;#39;s `max_receive_message_length` is enforced only against the already-decompressed message, so it provides no protection here. A single request is sufficient to OOM-kill the node.&lt;/p&gt;
&lt;p&gt;### PoC
A script that verifies the vulnerability is attached to the end of this report. Run it against a stock gRPC server using this library; the BEAM node&amp;#39;s memory usage will balloon and the VM will be OOM-killed after a single request.&lt;/p&gt;
&lt;p&gt;### Impact
This is a decompression bomb / denial-of-service vulnerability. Any service th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6ccx-9c9f-327w</guid>
    </item>
  </channel>
</rss>
