{"schema_version":"1.9.0","id":"CVE-2023-32731","published":"2023-06-09T10:54:08.472Z","modified":"2026-08-12T13:34:25.927999Z","aliases":["GHSA-cfgp-2977-2fmm","PYSEC-2026-1427"],"related":["CGA-w63x-w6j8-rw9j","SUSE-SU-2024:0573-1","openSUSE-SU-2024:13621-1","openSUSE-SU-2024:13634-1"],"summary":"Information leak in gRPC","details":"When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of HPACK tables between sender and receiver. If leveraged, say, between a proxy and a backend, this could lead to requests from the proxy being interpreted as containing headers from different proxy clients - leading to an information leak that can be used for privilege escalation or data exfiltration. We recommend upgrading beyond the commit contained in  https://github.com/grpc/grpc/pull/33005 https://github.com/grpc/grpc/pull/33005 \n","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc","events":[{"introduced":"358bfb581feeda5bf17dd3b96da1074d84a6ef8d"},{"fixed":"0bf4a618b17a3f0ed61c22364913c7f66fc1c61a"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.53"},{"last_affected":"1.54"},{"introduced":"1.53.0"},{"fixed":"1.55.0"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}},{"type":"GIT","repo":"https://github.com/grpc/grpc-go","events":[{"introduced":"357d7afc43fe0df74205b797525818fca8cd8f53"},{"fixed":"a75fd73d616bea96cfa1853b5bcd0aa762be0b7b"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.53.0"},{"fixed":"1.55.0"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/grpc/grpc-java","events":[{"introduced":"4ca6de0e8e52386301890b2860fb7a9a7c2c9b7c"},{"fixed":"e48040541bb2b42e2465344faee241a24d747466"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.53.0"},{"fixed":"1.55.0"}],"source":"CPE_RANGE"}}],"versions":["cmd/protoc-gen-go-grpc/v1.3.0","v1.53.0-dev"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32731.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["186848686847118742776406955756771337553","209791465984131615507118919125284817564","29686144606437801261731858559341686526","148346904065048773427365455448856051875"],"threshold":0.9},"id":"CVE-2023-32731-beda6ddb","signature_type":"Line","signature_version":"v1","source":"https://github.com/grpc/grpc-java/commit/e48040541bb2b42e2465344faee241a24d747466","target":{"file":"core/src/main/java/io/grpc/internal/GrpcUtil.java"}}],"vanir_signatures_modified":"2026-08-12T13:34:25Z"}}],"references":[{"type":"WEB","url":"https://github.com/grpc"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32731.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32731"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/32309"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33005"}],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-440"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32731.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}