Skip to content

Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec

High
glbrntt published GHSA-2jx2-qcm4-rf9h Jul 8, 2021

Package

grpc-swift (Swift Package Manager)

Affected versions

1.1.0, 1.1.1

Patched versions

1.2.0

Description

Impact

Affected gRPC Swift servers are vulnerable to precondition failures when parsing certain gRPC Web requests. This may lead to a denial of service.

Patches

The problem has been fixed in 1.2.0.

Workarounds

No workaround is available. Users must upgrade.

Severity

High

CVE ID

CVE-2021-36153

Weaknesses