pypi package report

Is grpcio safe?

5 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
0.80%

chance of exploitation in the next 30 days

xyz score
4.9

CyberXYZ composite, out of 10

fig. 01 — GHSA-p25m-jpj4-qcrr, the advisory selected below

// advisories

GHSA-p25m-jpj4-qcrr

HIGHCVE-2023-4785

Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.

Affected
>= 1.53.0, < 1.53.2, >= 1.54.0, < 1.54.3, >= 1.55.0, < 1.55.3
Fixed in
1.53.2
Weakness
CWE-248
Published
2023-09-13
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 01:46 UTC. The most recent advisory here was published 2023-09-13. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is grpcio safe? pypi package security report | CyberXYZ