{"id":"GHSA-xr7q-jx4m-x55m","summary":"Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go","details":"### Impact\nThis issue represents a potential PII concern.  If applications were printing or logging a context containing gRPC metadata, the affected versions will contain all the metadata, which may include private information.\n\n### Patches\nThe issue first appeared in 1.64.0 and is patched in 1.64.1 and 1.65.0\n\n### Workarounds\nIf using an affected version and upgrading is not possible, ensuring you do not log or print contexts will avoid the problem.\n","aliases":["GO-2024-2978"],"modified":"2026-07-17T21:08:28.065926066Z","published":"2024-07-05T20:07:01Z","database_specific":{"github_reviewed_at":"2024-07-05T20:07:01Z","nvd_published_at":null,"cwe_ids":["CWE-200"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/grpc/grpc-go/security/advisories/GHSA-xr7q-jx4m-x55m"},{"type":"WEB","url":"https://github.com/grpc/grpc-go/commit/ab292411ddc0f3b7a7786754d1fe05264c3021eb"},{"type":"PACKAGE","url":"https://github.com/grpc/grpc-go"}],"affected":[{"package":{"name":"google.golang.org/grpc","ecosystem":"Go","purl":"pkg:golang/google.golang.org/grpc"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.64.0"},{"fixed":"1.64.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-xr7q-jx4m-x55m/GHSA-xr7q-jx4m-x55m.json"}}],"schema_version":"1.9.0"}