Affected gRPC Swift servers are vulnerable to precondition failures when parsing certain gRPC Web requests. This may lead to a denial of service.
The problem has been fixed in 1.2.0.
No workaround is available. Users must upgrade.
| Score | Percentile |
|---|---|
| 1.36% | 79.60% |
No CVSS scores in this advisory.
| Type | Value |
|---|---|
| GHSA | GHSA-2jx2-qcm4-rf9h ↗ |
| CVE | CVE-2021-36153 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| swift | github.com/grpc/grpc-swift | < 1.2.0 | 1.2.0 | — |