VDB
Sign up
HIGH7.5

PYSEC-2026-1428

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Quick fix

PYSEC-2026-1428 — grpcio: upgrade to the fixed version with the command below.

pip install --upgrade 'grpcio>=1.53.2'

Details

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. 

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/grpcio
Introduced in: 1.55.0Fixed in: 1.55.3
Fixpip install --upgrade 'grpcio>=1.53.2'

References