9.2
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server.
'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process.
This issue affects grpc from 0.4.0 before 1.0.0.
'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process.
This issue affects grpc from 0.4.0 before 1.0.0.
AI Analysis
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and achieve remote code execution on the server
Basic Information
ID
CVE-2026-48853
Source
EEF
Published
Jun 15, 2026 at 21:56
Affected Product
Vendor
elixir-grpc
Product
grpc
Version
0.4.0
Affected Versions
elixir-grpc grpc 0.4.0
elixir-grpc grpc 25bcc569fe2cc4478531a6c546c923205fc751c9
elixir-grpc grpc 25bcc569fe2cc4478531a6c546c923205fc751c9
CWE Classification
AI Assessment
AI Score
9.2 / 10
AI Severity
Critical
Vendor
Elixir-GRPC
Product
grpc
Version
0.4.0