[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#gRPC

newsCRITICAL 9.2

gRPC Erlang Package Vulnerable to Remote Code Execution

The gRPC Erlang package is vulnerable to remote code execution with attacker-controlled gRPC payloads. Any unauthenticated peer that can reach a gRPC endpoint with `Content-Type: application/grpc+erlpack` can crash the entire BEAM node or achieve remote code execution inside the server process. Affected versions include `grpc` ≥ 0.4.0.

Aug 26, 20261 source
articleHIGH 7.1

Woodpecker CI gRPC Agent ID Spoofing Vulnerability Allows Cross-Tenant Impersonation

A vulnerability in Woodpecker CI's gRPC layer (CVE-2026-50141, CVSS 7.1) allows authenticated agents to impersonate other agents by spoofing the `agent_id` metadata. This issue enables cross-tenant impersonation, potentially leading to unauthorized access and privilege escalation. Affected versions include Woodpecker CI 3.0.0 to 3.14.1. Immediate patching or workarounds are recommended.

Jul 15, 20261 source