gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for -bin
suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309 https://www.google.com/url
{ "vanir_signatures": [ { "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "153505462668301892070772696189317306250", "40520222390141456988000868829229775555", "78570411478650308013931737040086710778", "60539704661294299732272537641085493035" ] }, "id": "CVE-2023-32732-c5f45506", "deprecated": false, "target": { "file": "core/src/main/java/io/grpc/internal/GrpcUtil.java" }, "signature_type": "Line", "source": "https://github.com/grpc/grpc-java/commit/4ca6de0e8e52386301890b2860fb7a9a7c2c9b7c" } ] }