Skip to content
Denial of Service Vulnerability in grpcurl Affects Fedora Systems

Denial of Service Vulnerability in grpcurl Affects Fedora Systems

First seen 11 Sep 2026, 04:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 06:15 UTC
  • CVE-2026-27145 allows denial of service via grpcurl on Fedora systems.
  • Affected versions include grpcurl 1.9.3 and earlier; upgrade to 1.9.4 is recommended.
  • Proof-of-concept code for the vulnerability was released shortly after its publication.

A denial of service vulnerability (CVE-2026-27145) has been identified in grpcurl, a command-line tool for interacting with gRPC servers, affecting Fedora systems. The vulnerability allows for excessive processing of DNS SAN entries, potentially leading to service disruption. Fedora versions 1.9.3 and earlier are impacted, with an update to version 1.9.4 available to mitigate the risk. The vulnerability was published on June 2, 2026, with a proof-of-concept released shortly after. Users are advised to upgrade their systems to the latest version to prevent exploitation. The advisory emphasizes the importance of keeping Linux systems secure and up to date. The update can be installed using the 'dnf' package manager. Both articles were published on September 11, 2026, highlighting the urgency of addressing this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-02
CVE-2026-27145 published
A denial of service vulnerability in grpcurl was disclosed, affecting Fedora systems.
Linuxsecurity
2026-06-03
First public PoC released
A proof-of-concept for CVE-2026-27145 was made publicly available, demonstrating the vulnerability.
Linuxsecurity
2026-09-11
Fedora advisory published
Fedora released an advisory urging users to update grpcurl to version 1.9.4 to mitigate the vulnerability.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-27145 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed