CVE-2026-48854: High-Severity DoS Flaw Found in Elixir gRPC Server
A high-severity vulnerability (CVSS 8.7) has been disclosed in the elixir-grpc server component, tracked as CVE-2026-48854 and published on August 25, 2026. The flaw allows unauthenticated remote attackers to send unbounded unary request payloads or slow-trickle streams, bypassing default timeout mechanisms and exhausting the host BEAM VM memory. This causes an immediate crash of the server node, classified as a Denial of Service under CWE-770 (resource allocation without limits). A proof-of-concept exploit exists, though the vulnerability has not been listed in the Known Exploited Vulnerabilities catalogue. Users are advised to upgrade to elixir-grpc version 1.0.0 or higher and apply additional mitigations such as reverse-proxy body size limits and WAF rate-limiting rules.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in