Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/elixir-grpc/grpc

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A critical deserialization vulnerability exists in elixir-grpc grpc versions starting from 0.4.0 before 1.0.0. The vulnerability arises from unsafe use of :erlang.binary_to_term/1 without safety options or size/type checks, allowing unauthenticated attackers to send crafted payloads that can exhaust the atom table and crash the BEAM VM or execute arbitrary code remotely.

Join the discussion

A high severity vulnerability in elixir-grpc grpc (versions from 0.4.0 before 1.0.0) allows unauthenticated remote attackers to cause a denial of service via a gzip decompression bomb. The issue arises because the grpc gzip decompressor calls :zlib.gunzip/1 directly on attacker-controlled data without limiting decompressed size or checking compression ratio, leading to excessive memory allocation and potential out-of-memory crashes.

Join the discussion

CVE-2026-48599 is an authorization bypass vulnerability in elixir-grpc grpc versions starting from 0.8.0 before 1.0.0. It allows authenticated attackers to override path-bound fields by supplying conflicting values via query strings or request bodies, causing handlers relying on these fields for authorization or ownership checks to be bypassed.

Join the discussion

CVE-2026-48854 is a high-severity vulnerability in elixir-grpc grpc versions starting from 0.3.1 before 1.0.0. It allows unauthenticated attackers to exhaust server memory and crash the BEAM node by sending a large or slow-trickle unary request body. The vulnerability arises because the server accumulates incoming request chunks into a single binary without any size limit and uses an infinite timeout when the grpc-timeout header is omitted, enabling indefinite memory growth.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/elixir-grpc/grpc
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses