Tag
#gRPC
newsCRITICAL 9.2
gRPC Erlang Package Vulnerable to Remote Code Execution
The gRPC Erlang package is vulnerable to remote code execution with attacker-controlled gRPC payloads. Any unauthenticated peer that can reach a gRPC endpoint with `Content-Type: application/grpc+erlpack` can crash the entire BEAM node or achieve remote code execution inside the server process. Affected versions include `grpc` ≥ 0.4.0.
articleHIGH 7.1
Woodpecker CI gRPC Agent ID Spoofing Vulnerability Allows Cross-Tenant Impersonation
A vulnerability in Woodpecker CI's gRPC layer (CVE-2026-50141, CVSS 7.1) allows authenticated agents to impersonate other agents by spoofing the `agent_id` metadata. This issue enables cross-tenant impersonation, potentially leading to unauthorized access and privilege escalation. Affected versions include Woodpecker CI 3.0.0 to 3.14.1. Immediate patching or workarounds are recommended.