{"schema_version":"1.9.0","id":"CVE-2023-4785","published":"2023-09-13T16:31:55.664Z","modified":"2026-08-12T14:51:33.684006Z","aliases":["GHSA-p25m-jpj4-qcrr","PYSEC-2026-1428"],"related":["CGA-vr55-29vv-j265","SUSE-SU-2024:0573-1","openSUSE-SU-2024:13621-1","openSUSE-SU-2024:13634-1"],"summary":"Denial of Service in gRPC Core","details":"Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc","events":[{"introduced":"7c0764918b9f33cab507ff483b4be849b0203ec4"},{"fixed":"afb307fb89ed83f358d82b5d359034a039a95e66"},{"introduced":"6847e05dbb8088a918f06e2231a405942b5c002d"},{"fixed":"868412b573a0663c8db41558498caf44098f4390"},{"introduced":"0bf4a618b17a3f0ed61c22364913c7f66fc1c61a"},{"fixed":"49dcbce9aba5f5f0959871354df90e38f0c5ed00"},{"introduced":"6e85620c7e258df79666a4743f862f2f82701c2d"},{"last_affected":"6e85620c7e258df79666a4743f862f2f82701c2d"}],"database_specific":{"cpe":["cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*","cpe:2.3:a:grpc:grpc:1.56.0:*:*:*:*:-:*:*"],"extracted_events":[{"introduced":"1.23.0"},{"fixed":"1.53.2"},{"introduced":"1.54.0"},{"fixed":"1.54.3"},{"introduced":"1.55.0"},{"fixed":"1.55.3"},{"introduced":"1.56.0"},{"last_affected":"1.56.0"}],"source":["CPE_RANGE","CPE_STRING"]}},{"type":"GIT","repo":"https://github.com/grpc/grpc-go","events":[{"introduced":"0ed709c4a71d08e5877b4bfb41c2747b0d1c3240"},{"last_affected":"0ed709c4a71d08e5877b4bfb41c2747b0d1c3240"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:1.56.0:*:*:*:*:-:*:*","extracted_events":[{"introduced":"1.56.0"},{"last_affected":"1.56.0"}],"source":"CPE_STRING"}},{"type":"GIT","repo":"https://github.com/grpc/grpc-java","events":[{"introduced":"e48040541bb2b42e2465344faee241a24d747466"},{"fixed":"958205ddb1ab7ec1f5bb92a1a812cf30fa753c36"},{"introduced":"d25095c2a714bb9abccdb6622a13b8bc768dc18a"},{"last_affected":"d25095c2a714bb9abccdb6622a13b8bc768dc18a"}],"database_specific":{"cpe":["cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*","cpe:2.3:a:grpc:grpc:1.56.0:*:*:*:*:-:*:*"],"extracted_events":[{"introduced":"1.55.0"},{"fixed":"1.55.3"},{"introduced":"1.56.0"},{"last_affected":"1.56.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["1.56.0","v1.56.0","v1.55.1","v1.54.2","v1.55.0","v1.54.1","v1.54.0","v1.56.0-dev"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4785.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["148529735852666896963464408479363428299","317277031500261825959216832225781396438","121902372659488140859240128980598754188","234477324359876819246199200915366156403"],"threshold":0.9},"id":"CVE-2023-4785-f337f5d8","signature_type":"Line","signature_version":"v1","source":"https://github.com/grpc/grpc-java/commit/958205ddb1ab7ec1f5bb92a1a812cf30fa753c36","target":{"file":"core/src/main/java/io/grpc/internal/GrpcUtil.java"}}],"vanir_signatures_modified":"2026-08-12T14:51:33Z"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4785.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4785"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33656"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33667"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33669"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33670"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33672"},{"type":"PACKAGE","url":"https://github.com/grpc/grpc"}],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-248"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4785.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.55.0"},{"last_affected":"1.55.2"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}