Skip to content

Uncontrolled Resource Consumption in LengthPrefixedMessageReader

High
glbrntt published GHSA-rxmj-hg9v-vp3p Jul 8, 2021

Package

grpc-swift (Swift Package Manager)

Affected versions

1.0.0, 1.1.0, 1.1.1

Patched versions

1.2.0

Description

Impact

Affected gRPC Swift clients and servers are vulnerable to uncontrolled resource consumption attacks. Excessive memory may be allocated when parsing messages. This can lead to a denial of service.

Patches

The problem has been fixed in 1.2.0.

Workarounds

No workaround is available. Users must upgrade.

Severity

High

CVE ID

CVE-2021-36155