Important Photon OS Security Update – PHSA-2020-0305

Updates of ['grpc'] packages of Photon OS have been released.Read More ...

Continue Reading
Node.js: HTTP2 ‘unknownProtocol’ cause Denial of Service by resource exhaustion

**Summary:** Node.js http2 server is vulnerable against denial of service attacks when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. ...

Continue Reading
[SECURITY] Fedora 34 Update: golang-github-containerd-ttrpc-1.1.0-1.fc34

GRPC for low-memory environments. The existing grpc-go project requires a lot of memory overhead for importing packages and at runtime. While this is great for many services with low den sity require ...

Continue Reading
CVE-2021-31350

An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-pri ...

Continue Reading
CVE-2021-41130

Extensible Service Proxy, a.k.a. ESP is a proxy which enables API management capabilities for JSON/REST or gRPC API services. ESPv1 can be configured to authenticate a JWT token. Its verified JWT clai ...

Continue Reading
CVE-2021-32781

An out-of-bounds memory read vulnerability was found in envoyproxy/envoy. When using one of the following envoy extensions, it is possible to modify and increase the request or response body size of t ...

Continue Reading
CVE-2021-36155

LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.Read More ...

Continue Reading
CVE-2021-36154

HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a single HTTP/2 frame, leading to Uncontrolled Recursio ...

Continue Reading

Back to Main

Subscribe for the latest news: