CVE-2026-84304: gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-Sep
Released
2026-09-05
Last Updated
2026-09-06
EPSS Score
0.41% (percentile: 34.7%)

Affected Products (34)

Other

  • 21742-17084
  • 21745-17084
  • 21648-17084
  • 21797-17084
  • 21666-17084
  • 21747-17084
  • 21675-17084
  • 21794-17084
  • 21795-17084
  • 21688-17084
  • 21768-17084
  • 21744-17084
  • 21769-17084
  • 21647-17084
  • 21687-17084
  • 21770-17084
  • 21743-17084
  • 21682-17084
  • 21771-17084
  • 21668-17084
  • 21796-17084
  • 21656-17084
  • 21655-17084
  • 21674-17084
  • 21741-17084
  • 21746-17084
  • 21652-17084
  • 17793-17084
  • 21705-17084
  • 21691-17084
  • 21772-17084
  • 21798-17084
  • 21799-17084
  • 21693-17084

Security Updates (1)

Revision History

  • 2026-09-05: Information published.
  • 2026-09-06: Information published.