{"id":"CVE-2023-4785","summary":"Denial of Service in gRPC Core","details":"Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.","aliases":["GHSA-p25m-jpj4-qcrr","PYSEC-2026-1428"],"modified":"2026-07-17T20:57:46.980522604Z","published":"2023-09-13T16:31:55.664Z","related":["SUSE-SU-2024:0573-1","openSUSE-SU-2024:13621-1","openSUSE-SU-2024:13634-1"],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-248"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4785.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.56.0"},{"last_affected":"1.56.1"},{"introduced":"1.55.0"},{"last_affected":"1.55.2"},{"introduced":"1.54.0"},{"last_affected":"1.54.2"},{"introduced":"1.53.0"},{"last_affected":"1.53.1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4785.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4785"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33656"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33667"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33669"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33670"},{"type":"FIX","url":"https://github.com/grpc/grpc/pull/33672"},{"type":"PACKAGE","url":"https://github.com/grpc/grpc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc-go","events":[{"introduced":"0ed709c4a71d08e5877b4bfb41c2747b0d1c3240"},{"last_affected":"0ed709c4a71d08e5877b4bfb41c2747b0d1c3240"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:1.56.0:*:*:*:*:-:*:*","extracted_events":[{"introduced":"1.56.0"},{"last_affected":"1.56.0"}],"source":"CPE_STRING"}}],"versions":["1.56.0","v1.56.0-dev"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-4785.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc-java","events":[{"introduced":"e48040541bb2b42e2465344faee241a24d747466"},{"fixed":"958205ddb1ab7ec1f5bb92a1a812cf30fa753c36"},{"introduced":"d25095c2a714bb9abccdb6622a13b8bc768dc18a"}],"database_specific":{"cpe":["cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*","cpe:2.3:a:grpc:grpc:1.56.0:*:*:*:*:-:*:*"],"extracted_events":[{"introduced":"1.55.0"},{"fixed":"1.55.3"},{"introduced":"1.56.0"},{"last_affected":"1.56.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["1.56.0","v1.55.1","v1.55.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-4785.json","vanir_signatures_modified":"2026-07-15T01:36:18Z","vanir_signatures":[{"id":"CVE-2023-4785-f337f5d8","signature_type":"Line","signature_version":"v1","source":"https://github.com/grpc/grpc-java/commit/958205ddb1ab7ec1f5bb92a1a812cf30fa753c36","target":{"file":"core/src/main/java/io/grpc/internal/GrpcUtil.java"},"deprecated":false,"digest":{"line_hashes":["148529735852666896963464408479363428299","317277031500261825959216832225781396438","121902372659488140859240128980598754188","234477324359876819246199200915366156403"],"threshold":0.9}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}