CVE 9.2 CRITICAL

Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc_CVE-2026-48853

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server.

'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process.

This issue affects grpc from 0.4.0 before 1.0.0.

AI Analysis

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and achieve remote code execution on the server

Basic Information

ID CVE-2026-48853
Source EEF
Published Jun 15, 2026 at 21:56

Affected Product

Vendor elixir-grpc
Product grpc
Version 0.4.0
Affected Versions elixir-grpc grpc 0.4.0
elixir-grpc grpc 25bcc569fe2cc4478531a6c546c923205fc751c9

CWE Classification

AI Assessment

AI Score 9.2 / 10
AI Severity Critical
Vendor Elixir-GRPC
Product grpc
Version 0.4.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.