{"id":"CVE-2024-7246","summary":"HPACK table poisoning in gRPC C++, Python & Ruby","details":"It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It's also possible to use this vulnerability to leak other clients HTTP header keys, but not values.\n\nThis occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table.\n\nPlease update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.","modified":"2026-08-12T15:13:34.372551Z","published":"2024-08-06T10:14:28.492Z","related":["SUSE-SU-2024:4393-1","SUSE-SU-2024:4400-1","SUSE-SU-2024:4401-1","SUSE-SU-2024:4428-1","SUSE-SU-2024:4429-1","SUSE-SU-2024:4436-1","openSUSE-SU-2025:15031-1"],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-440"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7246.json"},"references":[{"type":"WEB","url":"https://github.com/grpc"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7246.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-7246"},{"type":"REPORT","url":"https://github.com/grpc/grpc/issues/36245"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc","events":[{"introduced":"0"},{"fixed":"14bcda7eae0ee99f6a6dceb8d6cc23f49362f577"},{"introduced":"08cc1787de022069135004adfdd17938b5062319"},{"fixed":"b22b8e6c8855f958afda436d9f1def216085d505"},{"introduced":"0ef13a7555dbaadd4633399242524129eef5e231"},{"fixed":"0bab87ede8244a21fce01294a364cc9a7fc99ed8"},{"introduced":"a13178cb2537822bcdc552faba98fd9fa3c35b3e"},{"fixed":"f66fc914209e10fd2ec95ba45509f39285a23ad4"},{"introduced":"f78a54c5ad4e058734aa9b2beb9459940e4de342"},{"fixed":"c48c8fc22325ad867b67fec3ba58290ce90d4741"},{"introduced":"ac1418547838ab067a02af4402046f7bc1cbc44c"},{"fixed":"79fb6564995720f750ef7bc31523101b8961b911"},{"introduced":"b8a04acbbf18fd1c805e5d53d62ed9fa4721a4d1"},{"fixed":"aef0f0ccc3d21a328282144b8aa666f3c570dfb9"},{"introduced":"45479fda2a083c4e46310b9bb6e45e625e381269"},{"fixed":"c3407b728428b84f4c0b8c1b653094903fe2f462"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.58.3"},{"introduced":"1.59.0"},{"fixed":"1.59.5"},{"introduced":"1.60.0"},{"fixed":"1.60.2"},{"introduced":"1.61.0"},{"fixed":"1.61.3"},{"introduced":"1.62.0"},{"fixed":"1.62.3"},{"introduced":"1.63.0"},{"fixed":"1.63.2"},{"introduced":"1.64.0"},{"fixed":"1.64.3"},{"introduced":"1.65.0"},{"fixed":"1.65.4"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/grpc/grpc-go","events":[{"introduced":"0"},{"fixed":"bf05b9558c16677e362d231120f8213eb276d406"},{"introduced":"c68f4566b9cacdb11c42a6eb14ee66a33d9b7c12"},{"fixed":"d32e66ce27447a0a217464a36fdd3935801c0453"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.58.3"},{"introduced":"1.63.0"},{"fixed":"1.63.2"}],"source":"CPE_RANGE"}},{"type":"GIT","repo":"https://github.com/grpc/grpc-java","events":[{"introduced":"eb8b1d8379008ab89cade89392d265bed90a2692"},{"fixed":"41b192bb321ef3c67b06c8ee13f30a5c0e776f15"},{"introduced":"48aa1b88550d6ddac1955407a5eac511e0ebbde0"},{"fixed":"4e0116834af62e4a137dfaf39f0bbfb6d0e52ce6"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*","extracted_events":[{"introduced":"1.60.0"},{"fixed":"1.60.2"},{"introduced":"1.63.0"},{"fixed":"1.63.2"}],"source":"CPE_RANGE"}}],"versions":["1.53.0","1.53.1","1.53.2","1.54.0","1.54.1","1.54.3","1.55.0","1.55.1","1.55.3","1.55.4","1.56.0","1.56.1","1.56.2","1.56.3","1.56.4","1.57.0","1.57.1","1.58.0","1.58.1","1.58.2","1.59.0","1.59.1","1.59.2","1.59.3","1.59.4","1.60.0","1.60.1","1.61.0","1.61.1","1.61.2","1.62.0","1.62.1","1.62.2","1.63.0","1.63.1","1.64.0","1.64.1","1.64.2","1.65.0","1.65.1","1.65.2","1.65.3","v1.65.3","v1.65.2","v1.65.1","v1.65.0","v1.64.2","v1.63.1","v1.64.1","v1.64.0","v1.63.0","v1.62.2","v1.59.4","v1.61.2","v1.62.1","v1.60.1","v1.62.0","v1.61.1","v1.61.0","v1.58.2","v1.59.3","v1.60.0","v1.59.2","v1.59.1","v1.59.0","v1.58.1","v1.58.0","v1.58.0-pre1","v1.41.0-pre1","v1.33.0","v1.3.4","release-0_9_1-objectivec-0.5.1","release-0_9_0","release-0_6_0","release-0_6","release_test","v1.58.0-dev","v1.57.0-dev","v1.56.0-dev","gcp/observability/v1.0.0","stats/opencensus/v1.0.0","v1.55.0-dev","cmd/protoc-gen-go-grpc/v1.3.0","v1.53.0-dev","v1.52.0-dev","v1.51.0-dev","v1.50.0-dev","v1.49.0-dev","v1.48.0-dev","v1.47.0-dev","v1.46.0-dev","v1.45.0-dev","cmd/protoc-gen-go-grpc/v1.2.0","v1.44.0-dev","v1.43.0-dev","v1.42.0-dev","v1.41.0-dev","v1.40.0-dev","v1.39.0-dev","v1.38.0-dev","v1.37.0-dev","cmd/protoc-gen-go-grpc/v1.1.0","v1.36.0-dev","v1.35.0-dev","cmd/protoc-gen-go-grpc/v1.0.1","v1.34.0-dev","cmd/protoc-gen-go-grpc/v1.0.0","v1.33.0-dev","v1.32.0-dev","v1.31.0-dev","v1.30.0-dev.1","v1.30.0-dev","v1.29.0-dev","v1.28.0-pre","v1.27.0-pre","v1.2.0","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1-GA","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7246.json","vanir_signatures_modified":"2026-08-12T15:13:34Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/grpc/grpc-java/commit/41b192bb321ef3c67b06c8ee13f30a5c0e776f15","target":{"file":"core/src/main/java/io/grpc/internal/GrpcUtil.java"},"deprecated":false,"digest":{"line_hashes":["5234133516936529201855060918031647210","247430101873655922080843031035733074532","260976262506240152264252709226588657946","94080777265677368108166552244982612317"],"threshold":0.9},"id":"CVE-2024-7246-671aaa72","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["278747810669085701660566511551627379020","64807440934011919031643553310302048297","322958372820145568909636653434589875234","296051173635682802874341050146701286037"],"threshold":0.9},"id":"CVE-2024-7246-e3e39def","signature_type":"Line","signature_version":"v1","source":"https://github.com/grpc/grpc-java/commit/4e0116834af62e4a137dfaf39f0bbfb6d0e52ce6","target":{"file":"core/src/main/java/io/grpc/internal/GrpcUtil.java"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L"}]}