Skip to content

grpc: limit decompression size in legacy gzip Decompressor to prevent OOM - #9114

Merged
easwars merged 7 commits into
grpc:masterfrom
evilgensec:fix/legacy-decompressor-oom
May 27, 2026
Merged

grpc: limit decompression size in legacy gzip Decompressor to prevent OOM#9114
easwars merged 7 commits into
grpc:masterfrom
evilgensec:fix/legacy-decompressor-oom

Conversation

@evilgensec

@evilgensec evilgensec commented May 7, 2026

Copy link
Copy Markdown
Contributor

Summary

The legacy gzipDecompressor.Do() (used when a server is configured with the deprecated grpc.RPCDecompressor(grpc.NewGZIPDecompressor()) option) calls io.ReadAll(z) with no size bound. The size limit check happens after the full payload is materialized in memory:

// decompress():
uncompressed, err := dc.Do(r)          // io.ReadAll — full payload in memory
...
if len(uncompressed) > maxReceiveMessageSize {   // too late

A client can send a highly compressed gRPC frame (e.g., 1 KiB of gzip expanding to 1+ GiB) and force the server to buffer the entire expanded payload before the MaxRecvMsgSize limit fires.

The modern encoding.Compressor path already uses io.LimitReader(dcReader, limit+1) to prevent this (lines 993–1010). The deprecated path did not have the equivalent guard.

Fix

Wrap the reader passed to dc.Do with io.LimitReader(maxReceiveMessageSize+1), matching the behavior of the safe code path.

Scope

Only affects servers explicitly configured with grpc.RPCDecompressor(grpc.NewGZIPDecompressor()). The default server uses the encoding.Compressor path and is unaffected.

RELEASE NOTES:

  • grpc: limit decompression size in legacy gzip Decompressor to MaxRecvMsgSize

…ent OOM

The legacy gzipDecompressor.Do (used when the server is configured with
the deprecated grpc.RPCDecompressor option) calls io.ReadAll(z) with no
bound, materializing the entire decompressed payload in memory before
decompress() can check len(uncompressed) > maxReceiveMessageSize.

A client can send a highly compressed gRPC frame (e.g. 1 KiB of gzip
that expands to 1 GiB) and force the server to allocate and fill a
gigabyte buffer before the size limit fires. The default server path
(encoding.Compressor) already uses io.LimitReader(limit+1) to prevent
this; the deprecated path did not.

Fix: wrap the reader passed to dc.Do with io.LimitReader(maxReceiveMessageSize+1)
so that decompression stops at the limit boundary. The existing
len(uncompressed) > maxReceiveMessageSize check then fires as before,
but no more than maxReceiveMessageSize+1 bytes are ever buffered.
Copilot AI review requested due to automatic review settings May 7, 2026 06:22

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the deprecated grpc.Decompressor (legacy gzipDecompressor.Do() / grpc.RPCDecompressor(grpc.NewGZIPDecompressor())) receive path against decompression bombs by ensuring decompression cannot expand unbounded in memory before MaxRecvMsgSize is enforced.

Changes:

  • Wrap the legacy decompressor input reader with io.LimitReader(maxReceiveMessageSize+1) to bound decompression output prior to the post-decompression size check.
  • Add explanatory comments documenting the OOM risk and rationale for the limit.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread rpc_util.go Outdated
@codecov

codecov Bot commented May 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 83.10%. Comparing base (037c6ef) to head (b38765f).

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #9114      +/-   ##
==========================================
- Coverage   83.20%   83.10%   -0.11%     
==========================================
  Files         417      417              
  Lines       33648    33658      +10     
==========================================
- Hits        27998    27971      -27     
- Misses       4235     4256      +21     
- Partials     1415     1431      +16     
Files with missing lines Coverage Δ
rpc_util.go 83.50% <100.00%> (+0.43%) ⬆️

... and 25 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@easwars easwars self-assigned this May 12, 2026
@easwars easwars added the Type: Security A bug or other problem affecting security label May 12, 2026
@easwars easwars added this to the 1.82 Release milestone May 12, 2026
@easwars

easwars commented May 20, 2026

Copy link
Copy Markdown
Contributor

The legacy gzip compressor has been deprecated for over 8 years. So, while this fix is valid, it probably doesn't represent any real security vulnerability, because there is hardly going to be anyone using this.

@easwars easwars assigned arjan-bal and unassigned easwars May 20, 2026
@easwars
easwars requested a review from arjan-bal May 20, 2026 05:22
@easwars

easwars commented May 20, 2026

Copy link
Copy Markdown
Contributor

@arjan-bal for second set of eyes

@arjan-bal arjan-bal left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I took a look, and it seems like the current code is restricting the size of the compressed message rather than the decompressed payload. If the goal was to check the compressed size, a more straightforward approach might be to check the length of the message buffer (d.Len()) directly.

However, it looks like the check for the compressed message length already exists here, which might make this current fix redundant.

If the goal is to protect against zip bombs, we'll need to limit the decompressed size instead. I think a good way to handle this would be to wrap the gzip reader in an io.LimitReader here.

From there, we could check if the limit was reached, similar to how it's handled in the new gzip compressor here.

Note that it's not possible to pass extra params to the Do method, so we may need to type assert the reader to be a gzip decompressor to pass the max message size.

Per review feedback, the previous patch wrapped the *compressed* reader
with io.LimitReader, which only constrained input bytes — that check
already exists in parser.recvMsg via MaxRecvMsgSize. It did not bound
the decompressed payload, so a zip-bomb frame could still expand
unbounded inside io.ReadAll.

Move the LimitReader so it wraps the gzip.Reader output instead of the
input. Since Decompressor.Do has no max-size parameter, add an internal
doWithMaxSize helper on *gzipDecompressor and type-assert at the
decompress() call site to invoke it. Third-party Decompressor
implementations keep the existing Do behavior.

Add TestDecompress_LegacyGzipBomb and TestDecompress_LegacyGzipUnderLimit
covering the over-limit and under-limit cases on the legacy path.
@evilgensec

Copy link
Copy Markdown
Contributor Author

Thanks for the careful look @arjan-bal — you're right, and I've reworked the fix in 50ab251.

You correctly pointed out that the previous version wrapped io.LimitReader around the compressed input, which is redundant with the MaxRecvMsgSize check in parser.recvMsg. The decompressed payload was still unbounded, so the OOM window stayed open.

The updated patch moves the io.LimitReader so it wraps the *gzip.Reader output instead of the input — matching the pattern at lines 996–1013 in the modern encoding.Compressor path. Since Decompressor.Do(r io.Reader) can't take a size parameter, I added an internal doWithMaxSize helper on *gzipDecompressor and type-assert at the decompress() call site to invoke it. Third-party Decompressor implementations fall through to the original Do and are unaffected.

Two tests cover this: TestDecompress_LegacyGzipBomb (1 MiB-of-zeros payload, 1 KiB receive limit → ResourceExhausted instead of full expansion) and TestDecompress_LegacyGzipUnderLimit (legitimate traffic still decompresses correctly).

PTAL when you have a chance.

@evilgensec
evilgensec requested a review from arjan-bal May 21, 2026 07:55

@arjan-bal arjan-bal left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, just a couple of minor comments.

Comment thread rpc_util_test.go Outdated
Comment thread rpc_util_test.go Outdated
- Check only status.Code in TestDecompress_LegacyGzipBomb instead of
  comparing the full error string, so the test isn't tied to the exact
  message format.
- Rename compressWithDeterministicError to mustCompress; the previous
  name suggested behavior the helper does not have (it just compresses
  and fails the test on error). Internal error messages updated to match.
@evilgensec
evilgensec requested a review from arjan-bal May 21, 2026 08:35

@arjan-bal arjan-bal left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks for the fix! Assigning back to @easwars for a second review since the PR has changed since his previous approval.

@arjan-bal

Copy link
Copy Markdown
Contributor

The build seems to have broken after renaming the compressWithDeterministicError. Can you please fix it?

A new caller of the helper was added on master while this branch was
open, breaking the build after the rename. Update the merged-in
TestDecompress_ClosesReader to use mustCompress.
Comment thread rpc_util_test.go Outdated
@linux-foundation-easycla

linux-foundation-easycla Bot commented May 21, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

Move the two standalone TestDecompress_LegacyGzip* tests into the
TestDecompress table so the bomb case asserts the exact error
message, which pins decompress() to having read at most
maxReceiveMessageSize+1 bytes.
@evilgensec
evilgensec force-pushed the fix/legacy-decompressor-oom branch from a4d9e24 to b38765f Compare May 21, 2026 14:32
@evilgensec

Copy link
Copy Markdown
Contributor Author

Dear Team, anything else needed to merge into main?

@easwars easwars changed the title rpc_util: limit decompression size in legacy gzipDecompressor to prevent OOM grpc: limit decompression size in legacy gzipDecompressor to prevent OOM May 27, 2026
@easwars easwars changed the title grpc: limit decompression size in legacy gzipDecompressor to prevent OOM grpc: limit decompression size in legacy gzip Decompressor to prevent OOM May 27, 2026
@easwars
easwars merged commit 761e655 into grpc:master May 27, 2026
17 checks passed
goingforstudying-ctrl added a commit to goingforstudying-ctrl/grpc-go that referenced this pull request Jun 21, 2026
eleboucher pushed a commit to eleboucher/talos-mcp that referenced this pull request Jul 1, 2026
…(#17)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.81.1` → `v1.82.0` | ![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.82.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.81.1/v1.82.0?slim=true) |

---

### Release Notes

<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>

### [`v1.82.0`](https://github.com/grpc/grpc-go/releases/tag/v1.82.0): Release 1.82.0

[Compare Source](grpc/grpc-go@v1.81.1...v1.82.0)

### Behavior Changes

- server: Remove support for `GRPC_GO_EXPERIMENTAL_DISABLE_STRICT_PATH_CHECKING` environment varibale. Strict incoming RPC path validation (which has been the default since `v1.79.3`) can no longer be disabled. ([#&#8203;9112](grpc/grpc-go#9112))
- transport: Add environment variable to change the default max header list size from `16MB` to `8KB`. This may be enabled by setting `GRPC_GO_EXPERIMENTAL_ENABLE_8KB_DEFAULT_HEADER_LIST_SIZE=true`. This will be enabled by default in a subsequent release. ([#&#8203;9019](grpc/grpc-go#9019))
- balancer: Load Balancing policy registry is now case-sensitive.  Set `GRPC_GO_EXPERIMENTAL_CASE_SENSITIVE_BALANCER_REGISTRIES=false` (and file an issue) to revert to case-insensitive behavior. ([#&#8203;9017](grpc/grpc-go#9017))

### New Features

- experimental/stats: Expose a new API, `NewContextWithLabelCallback`, to register a callback that is invoked when telemetry labels are added. ([#&#8203;8877](grpc/grpc-go#8877))
  - Special Thanks: [@&#8203;seth-epps](https://github.com/seth-epps)
- client: Return a portion of the response body in the error message, when the client receives an unexpected non-gRPC HTTP response, to make debugging easier. ([#&#8203;8929](grpc/grpc-go#8929))
  - Special Thanks: [@&#8203;chengxilo](https://github.com/chengxilo)
- server: Add environment variable `GRPC_GO_SERVER_GOROUTINE_LABELS` that controls setting `runtime/pprof.Labels` on goroutines spawned by the server. Set `GRPC_GO_SERVER_GOROUTINE_LABELS=grpc.method=true` to add the `grpc.method` label on goroutines spawned to handle incoming requests. ([#&#8203;9082](grpc/grpc-go#9082))
  - Special Thanks: [@&#8203;dfinkel](https://github.com/dfinkel)

### Bug Fixes

- xds/server: Fix a memory leak of HTTP filter instances occurring when route configurations are updated in-place during a Route Discovery Service (RDS) update. ([#&#8203;9138](grpc/grpc-go#9138))
- grpc: In the deprecated `gzip` Compressor (used via the deprecated `WithCompressor` dial option), enforce the `MaxRecvMsgSize` limit on the decompressed message buffer, preventing excessive memory allocation from highly compressed payloads. ([#&#8203;9114](grpc/grpc-go#9114))
  - Special Thanks: [@&#8203;evilgensec](https://github.com/evilgensec)
- stats/opentelemetry: Record retry attempts, `grpc.previous-rpc-attempts`, at the call level and not the attempt level. ([#&#8203;8923](grpc/grpc-go#8923))
- encoding: Ensure `Close()` is always called on readers returned from `Compressor.Decompress` if possible. ([#&#8203;9135](grpc/grpc-go#9135))
- channelz: Fix the `LastMessageSentTimestamp` and `LastMessageReceivedTimestamp` fields in `SocketMetrics` to ensure they contain correct timestamp values. ([#&#8203;9109](grpc/grpc-go#9109))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEwMS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL21pbm9yIl19-->

Reviewed-on: https://git.erwanleboucher.dev/eleboucher/talos-mcp/pulls/17
eleboucher pushed a commit to eleboucher/runner-k8s-plugin that referenced this pull request Jul 6, 2026
…(#77)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.81.1` → `v1.82.0` | ![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.82.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.81.1/v1.82.0?slim=true) |

---

### Release Notes

<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>

### [`v1.82.0`](https://github.com/grpc/grpc-go/releases/tag/v1.82.0): Release 1.82.0

[Compare Source](grpc/grpc-go@v1.81.1...v1.82.0)

### Behavior Changes

- server: Remove support for `GRPC_GO_EXPERIMENTAL_DISABLE_STRICT_PATH_CHECKING` environment varibale. Strict incoming RPC path validation (which has been the default since `v1.79.3`) can no longer be disabled. ([#&#8203;9112](grpc/grpc-go#9112))
- transport: Add environment variable to change the default max header list size from `16MB` to `8KB`. This may be enabled by setting `GRPC_GO_EXPERIMENTAL_ENABLE_8KB_DEFAULT_HEADER_LIST_SIZE=true`. This will be enabled by default in a subsequent release. ([#&#8203;9019](grpc/grpc-go#9019))
- balancer: Load Balancing policy registry is now case-sensitive.  Set `GRPC_GO_EXPERIMENTAL_CASE_SENSITIVE_BALANCER_REGISTRIES=false` (and file an issue) to revert to case-insensitive behavior. ([#&#8203;9017](grpc/grpc-go#9017))

### New Features

- experimental/stats: Expose a new API, `NewContextWithLabelCallback`, to register a callback that is invoked when telemetry labels are added. ([#&#8203;8877](grpc/grpc-go#8877))
  - Special Thanks: [@&#8203;seth-epps](https://github.com/seth-epps)
- client: Return a portion of the response body in the error message, when the client receives an unexpected non-gRPC HTTP response, to make debugging easier. ([#&#8203;8929](grpc/grpc-go#8929))
  - Special Thanks: [@&#8203;chengxilo](https://github.com/chengxilo)
- server: Add environment variable `GRPC_GO_SERVER_GOROUTINE_LABELS` that controls setting `runtime/pprof.Labels` on goroutines spawned by the server. Set `GRPC_GO_SERVER_GOROUTINE_LABELS=grpc.method=true` to add the `grpc.method` label on goroutines spawned to handle incoming requests. ([#&#8203;9082](grpc/grpc-go#9082))
  - Special Thanks: [@&#8203;dfinkel](https://github.com/dfinkel)

### Bug Fixes

- xds/server: Fix a memory leak of HTTP filter instances occurring when route configurations are updated in-place during a Route Discovery Service (RDS) update. ([#&#8203;9138](grpc/grpc-go#9138))
- grpc: In the deprecated `gzip` Compressor (used via the deprecated `WithCompressor` dial option), enforce the `MaxRecvMsgSize` limit on the decompressed message buffer, preventing excessive memory allocation from highly compressed payloads. ([#&#8203;9114](grpc/grpc-go#9114))
  - Special Thanks: [@&#8203;evilgensec](https://github.com/evilgensec)
- stats/opentelemetry: Record retry attempts, `grpc.previous-rpc-attempts`, at the call level and not the attempt level. ([#&#8203;8923](grpc/grpc-go#8923))
- encoding: Ensure `Close()` is always called on readers returned from `Compressor.Decompress` if possible. ([#&#8203;9135](grpc/grpc-go#9135))
- channelz: Fix the `LastMessageSentTimestamp` and `LastMessageReceivedTimestamp` fields in `SocketMetrics` to ensure they contain correct timestamp values. ([#&#8203;9109](grpc/grpc-go#9109))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEwMS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL21pbm9yIl19-->

Reviewed-on: https://git.erwanleboucher.dev/eleboucher/runner-k8s-plugin/pulls/77
wu pushed a commit to wu/keyop-messenger that referenced this pull request Jul 18, 2026
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.81.1` → `v1.82.0` | ![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.82.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.81.1/v1.82.0?slim=true) |

---

### Release Notes

<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>

### [`v1.82.0`](https://github.com/grpc/grpc-go/releases/tag/v1.82.0): Release 1.82.0

[Compare Source](grpc/grpc-go@v1.81.1...v1.82.0)

### Behavior Changes

- server: Remove support for `GRPC_GO_EXPERIMENTAL_DISABLE_STRICT_PATH_CHECKING` environment varibale. Strict incoming RPC path validation (which has been the default since `v1.79.3`) can no longer be disabled. ([#&#8203;9112](grpc/grpc-go#9112))
- transport: Add environment variable to change the default max header list size from `16MB` to `8KB`. This may be enabled by setting `GRPC_GO_EXPERIMENTAL_ENABLE_8KB_DEFAULT_HEADER_LIST_SIZE=true`. This will be enabled by default in a subsequent release. ([#&#8203;9019](grpc/grpc-go#9019))
- balancer: Load Balancing policy registry is now case-sensitive.  Set `GRPC_GO_EXPERIMENTAL_CASE_SENSITIVE_BALANCER_REGISTRIES=false` (and file an issue) to revert to case-insensitive behavior. ([#&#8203;9017](grpc/grpc-go#9017))

### New Features

- experimental/stats: Expose a new API, `NewContextWithLabelCallback`, to register a callback that is invoked when telemetry labels are added. ([#&#8203;8877](grpc/grpc-go#8877))
  - Special Thanks: [@&#8203;seth-epps](https://github.com/seth-epps)
- client: Return a portion of the response body in the error message, when the client receives an unexpected non-gRPC HTTP response, to make debugging easier. ([#&#8203;8929](grpc/grpc-go#8929))
  - Special Thanks: [@&#8203;chengxilo](https://github.com/chengxilo)
- server: Add environment variable `GRPC_GO_SERVER_GOROUTINE_LABELS` that controls setting `runtime/pprof.Labels` on goroutines spawned by the server. Set `GRPC_GO_SERVER_GOROUTINE_LABELS=grpc.method=true` to add the `grpc.method` label on goroutines spawned to handle incoming requests. ([#&#8203;9082](grpc/grpc-go#9082))
  - Special Thanks: [@&#8203;dfinkel](https://github.com/dfinkel)

### Bug Fixes

- xds/server: Fix a memory leak of HTTP filter instances occurring when route configurations are updated in-place during a Route Discovery Service (RDS) update. ([#&#8203;9138](grpc/grpc-go#9138))
- grpc: In the deprecated `gzip` Compressor (used via the deprecated `WithCompressor` dial option), enforce the `MaxRecvMsgSize` limit on the decompressed message buffer, preventing excessive memory allocation from highly compressed payloads. ([#&#8203;9114](grpc/grpc-go#9114))
  - Special Thanks: [@&#8203;evilgensec](https://github.com/evilgensec)
- stats/opentelemetry: Record retry attempts, `grpc.previous-rpc-attempts`, at the call level and not the attempt level. ([#&#8203;8923](grpc/grpc-go#8923))
- encoding: Ensure `Close()` is always called on readers returned from `Compressor.Decompress` if possible. ([#&#8203;9135](grpc/grpc-go#9135))
- channelz: Fix the `LastMessageSentTimestamp` and `LastMessageReceivedTimestamp` fields in `SocketMetrics` to ensure they contain correct timestamp values. ([#&#8203;9109](grpc/grpc-go#9109))

</details>

---

### Configuration

📅 **Schedule**: (in timezone America/Los_Angeles)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI3MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: Renovate Bot <renovate-bot@geekfarm.org>
Reviewed-on: https://git.geekfarm.org/wu/keyop-messenger/pulls/7
nschloe pushed a commit to live-clones/forgejo that referenced this pull request Jul 23, 2026
…/forgejo) (#13580)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.79.3` → `v1.82.1` | ![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.82.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.79.3/v1.82.1?slim=true) |

---

### gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
[GHSA-hrxh-6v49-42gf](GHSA-hrxh-6v49-42gf)

<details>
<summary>More information</summary>

#### Details
Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:

- Authorization Bypass (Fail-Open) when translating xDS RBAC policies containing `Metadata` or `RequestedServerName` fields.
- Denial of Service (High CPU Consumption) due to an HTTP/2 Rapid Reset mitigation bypass during client-initiated stream resets.
- Denial of Service (Server Panic) when parsing crafted xDS RBAC policies containing `NOT` rules around unsupported fields.

##### Impact
_What kind of vulnerability is it? Who is impacted?_

##### xDS RBAC Authorization Bypass via `Metadata` & `RequestedServerName` matchers

- Affected Component: xDS RBAC
- Impact: When building policy matchers for gRPC RBAC from xDS configurations, unsupported `permission` and `principal` rules (specifically `Metadata` and `RequestedServerName`) were silently ignored and treated as no-ops.
  - If an authorization policy relied purely on these matchers for access control, treating those rules as no-ops effectively removed the restrictions.
- If these unsupported rules were nested inside logical `NOT` rules (`Permission_NotRule` / `Principal_NotId`) or multi-condition `OR/AND` rules, silently dropping them changed the boolean logic flow of the authorization engine.

As a result, policy evaluation decisions could fail open, allowing unauthorized clients to access protected gRPC services or resources.

##### HTTP/2 Rapid Reset Mitigation Bypass / Denial of Service via Stream Aborts

- Affected Component: HTTP/2 transport
- Impact: Earlier mitigations in grpc-go for HTTP/2 Rapid Reset only applied threshold checks to items that directly resulted in control frames being written back to the wire, such as `SETTINGS` ACKs or server-initiated `RST_STREAM`s.

When a client initiated a rapid flood of stream creation (`HEADERS`) immediately followed by stream termination `RST_STREAM`, items queued up in the control buffer without counting against the transport response frame threshold. An attacker can repeatedly trigger this flood sequence to bypass reader blocking, resulting in high CPU usage, and Denial of Service (DoS).

##### Denial of Service (Panic) in xDS RBAC Engine via Unsupported Fields inside NOT Rules

- Affected Component: xDS RBAC
- Impact: The xDS RBAC policy translators recursively generate matchers for nested rules. When a `NOT` rule wrapped an unsupported or unhandled field (such as `SourcedMetadata`), the recursive step returned an empty matcher. This could result in a runtime panic when the RBAC engine attempts to authorize an incoming request.

An attacker or misconfigured/malicious xDS management server delivering an LDS/RDS update containing a `NOT` rule around an unhandled field causes the gRPC server process to crash immediately (CWE-248 / Denial of Service).

##### Patches
_Has the problem been patched? What versions should users upgrade to?_

All three issues have been fixed in `master` and will be released in 1.82.1 shortly.

##### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_

If upgrading grpc-go immediately is not possible, apply the following workarounds based on your deployment architecture:

* For xDS RBAC Vulnerabilities & Panics: Ensure that upstream xDS management servers do not push RBAC policies containing `Metadata`, `RequestedServerName`, or `NOT` rules wrapping unsupported fields (such as `SourcedMetadata`) to grpc-go servers.
* For HTTP/2 Rapid Reset DOS: Configure upstream reverse proxies or load balancers (such as Envoy) with strict HTTP/2 `max_concurrent_streams` limits and active rate limiting on `RST_STREAM` frequency per connection.

##### Severity

  | Vulnerability | Qualitative Severity | Approximate CVSS v3.1 Score | Primary Impact |
  | :--- | :--- | :--- | :--- |
  | **xDS RBAC Authorization Bypass** | **High** | `8.2` | Unauthorized Access / Fail-Open |
  | **HTTP/2 Rapid Reset DOS Bypass** | **High** | `7.5` | High CPU Consumption / Denial of Service |
  | **xDS RBAC Engine Server Panic** | **Medium** | `5.9` | Process Crash / Denial of Service |

#### Severity
- CVSS Score: 8.8 / 10 (High)
- Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N`

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf](https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf)
- [https://github.com/grpc/grpc-go/pull/9236](https://github.com/grpc/grpc-go/pull/9236)
- [https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935](https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935)
- [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go)
- [https://github.com/grpc/grpc-go/releases/tag/v1.82.1](https://github.com/grpc/grpc-go/releases/tag/v1.82.1)

This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-hrxh-6v49-42gf) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>

### [`v1.82.1`](https://github.com/grpc/grpc-go/releases/tag/v1.82.1): Release 1.82.1

[Compare Source](grpc/grpc-go@v1.82.0...v1.82.1)

### Security

- server: Stop reading from the connection when flooded by HTTP/2 frames.  The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`.
- xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields.  If present in a DENY rule, previously these would be ignored and fail-open.
- xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions.
- xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`.

### [`v1.82.0`](https://github.com/grpc/grpc-go/releases/tag/v1.82.0): Release 1.82.0

[Compare Source](grpc/grpc-go@v1.81.1...v1.82.0)

### Behavior Changes

- server: Remove support for `GRPC_GO_EXPERIMENTAL_DISABLE_STRICT_PATH_CHECKING` environment varibale. Strict incoming RPC path validation (which has been the default since `v1.79.3`) can no longer be disabled. ([#&#8203;9112](grpc/grpc-go#9112))
- transport: Add environment variable to change the default max header list size from `16MB` to `8KB`. This may be enabled by setting `GRPC_GO_EXPERIMENTAL_ENABLE_8KB_DEFAULT_HEADER_LIST_SIZE=true`. This will be enabled by default in a subsequent release. ([#&#8203;9019](grpc/grpc-go#9019))
- balancer: Load Balancing policy registry is now case-sensitive.  Set `GRPC_GO_EXPERIMENTAL_CASE_SENSITIVE_BALANCER_REGISTRIES=false` (and file an issue) to revert to case-insensitive behavior. ([#&#8203;9017](grpc/grpc-go#9017))

### New Features

- experimental/stats: Expose a new API, `NewContextWithLabelCallback`, to register a callback that is invoked when telemetry labels are added. ([#&#8203;8877](grpc/grpc-go#8877))
  - Special Thanks: [@&#8203;seth-epps](https://github.com/seth-epps)
- client: Return a portion of the response body in the error message, when the client receives an unexpected non-gRPC HTTP response, to make debugging easier. ([#&#8203;8929](grpc/grpc-go#8929))
  - Special Thanks: [@&#8203;chengxilo](https://github.com/chengxilo)
- server: Add environment variable `GRPC_GO_SERVER_GOROUTINE_LABELS` that controls setting `runtime/pprof.Labels` on goroutines spawned by the server. Set `GRPC_GO_SERVER_GOROUTINE_LABELS=grpc.method=true` to add the `grpc.method` label on goroutines spawned to handle incoming requests. ([#&#8203;9082](grpc/grpc-go#9082))
  - Special Thanks: [@&#8203;dfinkel](https://github.com/dfinkel)

### Bug Fixes

- xds/server: Fix a memory leak of HTTP filter instances occurring when route configurations are updated in-place during a Route Discovery Service (RDS) update. ([#&#8203;9138](grpc/grpc-go#9138))
- grpc: In the deprecated `gzip` Compressor (used via the deprecated `WithCompressor` dial option), enforce the `MaxRecvMsgSize` limit on the decompressed message buffer, preventing excessive memory allocation from highly compressed payloads. ([#&#8203;9114](grpc/grpc-go#9114))
  - Special Thanks: [@&#8203;evilgensec](https://github.com/evilgensec)
- stats/opentelemetry: Record retry attempts, `grpc.previous-rpc-attempts`, at the call level and not the attempt level. ([#&#8203;8923](grpc/grpc-go#8923))
- encoding: Ensure `Close()` is always called on readers returned from `Compressor.Decompress` if possible. ([#&#8203;9135](grpc/grpc-go#9135))
- channelz: Fix the `LastMessageSentTimestamp` and `LastMessageReceivedTimestamp` fields in `SocketMetrics` to ensure they contain correct timestamp values. ([#&#8203;9109](grpc/grpc-go#9109))

### [`v1.81.1`](https://github.com/grpc/grpc-go/releases/tag/v1.81.1): Release 1.81.1

[Compare Source](grpc/grpc-go@v1.81.0...v1.81.1)

### Security

- xds/rbac: Fix a potential authorization bypass caused by incorrectly falling through URI/DNS SANs to Subject Distinguished Name (DN) when matching the authenticated principal name. With this fix, only the first non-empty identity source will be used, as per [gRFC A41](https://github.com/grpc/proposal/blob/master/A41-xds-rbac.md). ([#&#8203;9111](grpc/grpc-go#9111))
  - Special Thanks: [@&#8203;al4an444](https://github.com/al4an444)

### Bug Fixes

- otel: Segregate client and server RPC information used for metrics and traces, to avoid one overwriting the other. ([#&#8203;9081](grpc/grpc-go#9081))

### [`v1.81.0`](https://github.com/grpc/grpc-go/releases/tag/v1.81.0): Release 1.81.0

[Compare Source](grpc/grpc-go@v1.80.0...v1.81.0)

### Behavior Changes

- balancer/rls: Switch gauge metrics to asynchronous emission (once per collection cycle) to reduce telemetry noise and align with other gRPC language implementations. ([#&#8203;8808](grpc/grpc-go#8808))

### Dependencies

- Minimum supported Go version is now 1.25. ([#&#8203;8969](grpc/grpc-go#8969))

### Bug Fixes

- xds: Use the leaf cluster's security config for the TLS handshake instead of the aggregate cluster's config. ([#&#8203;8956](grpc/grpc-go#8956))
- transport: Send a `RST_STREAM` when receiving an `END_STREAM` when the stream is not already half-closed. ([#&#8203;8832](grpc/grpc-go#8832))
- xds: Fix ADS resource name validation to prevent a panic. ([#&#8203;8970](grpc/grpc-go#8970))

### New Features

- grpc/stats: Add support for custom labels in per-call metrics ([gRFC A108](https://github.com/grpc/proposal/blob/master/A108-otel-custom-per-call-label.md)). ([#&#8203;9008](grpc/grpc-go#9008))
- xds: Add support for Server Name Indication (SNI) and SAN validation ([gRFC A101](https://github.com/grpc/proposal/blob/master/A101-SNI-setting-and-SNI-SAN-validation.md)). Disabled by default. To enable, set `GRPC_EXPERIMENTAL_XDS_SNI=true` environment variable. ([#&#8203;9016](grpc/grpc-go#9016))
- xds: Add support to control which fields get propagated from ORCA backend metric reports to LRS load reports ([gRFC A85](https://github.com/grpc/proposal/blob/master/A85-lrs-custom-metrics-changes.md)). Disabled by default. To enable, set `GRPC_EXPERIMENTAL_XDS_ORCA_LRS_PROPAGATION=true`. ([#&#8203;9005](grpc/grpc-go#9005))
- xds: Add metrics to track xDS client connectivity and cached resource state ([gRFC A78](https://github.com/grpc/proposal/blob/master/A78-grpc-metrics-wrr-pf-xds.md)). ([#&#8203;8807](grpc/grpc-go#8807))
- stats/otel: Enhance `grpc.subchannel.disconnections` metric by adding disconnection reason to the `grpc.disconnect_error` label ([gRFC A94](https://github.com/grpc/proposal/blob/master/A94-subchannel-otel-metrics.md)). This provides granular insights into why subchannels are closing. ([#&#8203;8973](grpc/grpc-go#8973))
- mem: Add `mem.Buffer.Slice()` API to slice the buffer like a slice. ([#&#8203;8977](grpc/grpc-go#8977))
  - Special Thanks: [@&#8203;ash2k](https://github.com/ash2k)

### Performance Improvements

- alts: Pool read buffers to lower memory utilization when sockets are unreadable. ([#&#8203;8964](grpc/grpc-go#8964))
- transport: Pool HTTP/2 framer read buffers to reduce idle memory consumption. Currently limited to Linux for ALTS and non-encrypted transports (TCP, Unix). To disable, set `GRPC_GO_EXPERIMENTAL_HTTP_FRAMER_READ_BUFFER_POOLING=false` and report any issues. ([#&#8203;9032](grpc/grpc-go#9032))

### [`v1.80.0`](https://github.com/grpc/grpc-go/releases/tag/v1.80.0): Release 1.80.0

[Compare Source](grpc/grpc-go@v1.79.3...v1.80.0)

### Behavior Changes

- balancer: log a warning if a balancer is registered with uppercase letters, as balancer names should be lowercase. In a future release, balancer names will be treated as case-insensitive; see [#&#8203;5288](grpc/grpc-go#5288) for details. ([#&#8203;8837](grpc/grpc-go#8837))
- xds: update resource error handling and re-resolution logic ([#&#8203;8907](grpc/grpc-go#8907))
  - Re-resolve all `LOGICAL_DNS` clusters simultaneously when re-resolution is requested.
  - Fail all in-flight RPCs immediately upon receipt of listener or route resource errors, instead of allowing them to complete.

### Bug Fixes

- xds: support the LB policy configured in `LOGICAL_DNS` cluster resources instead of defaulting to `pick_first`. ([#&#8203;8733](grpc/grpc-go#8733))
- credentials/tls: perform per-RPC authority validation against the leaf certificate instead of the entire peer certificate chain. ([#&#8203;8831](grpc/grpc-go#8831))
- xds: enabling A76 ring hash endpoint keys no longer causes EDS resources with invalid proxy metadata to be NACKed when HTTP CONNECT (gRFC A86) is disabled. ([#&#8203;8875](grpc/grpc-go#8875))
- xds: validate that the sum of endpoint weights in a locality does not exceed the maximum `uint32` value. ([#&#8203;8899](grpc/grpc-go#8899))
  - Special Thanks: [@&#8203;RAVEYUS](https://github.com/RAVEYUS)
- xds: fix incorrect proto field access in the weighted round robin (WRR) configuration where `blackout_period` was used instead of `weight_expiration_period`. ([#&#8203;8915](grpc/grpc-go#8915))
  - Special Thanks: [@&#8203;gregbarasch](https://github.com/gregbarasch)
- xds/rbac: handle addresses with ports in IP matchers. ([#&#8203;8990](grpc/grpc-go#8990))

### New Features

- ringhash: enable gRFC A76 (endpoint hash keys and request hash headers) by default. ([#&#8203;8922](grpc/grpc-go#8922))

### Performance Improvements

- credentials/alts: pool write buffers to reduce memory allocations and usage. ([#&#8203;8919](grpc/grpc-go#8919))
- grpc: enable the use of pooled write buffers for buffering HTTP/2 frame writes by default. This reduces memory usage when connections are idle. Use the [WithSharedWriteBuffer](https://pkg.go.dev/google.golang.org/grpc#WithSharedWriteBuffer) dial option or the [SharedWriteBuffer](https://pkg.go.dev/google.golang.org/grpc#SharedWriteBuffer) server option to disable this feature. ([#&#8203;8957](grpc/grpc-go#8957))
- xds/priority: stop caching child LB policies removed from the configuration. This will help reduce memory and cpu usage when localities are constantly switching between priorities. ([#&#8203;8997](grpc/grpc-go#8997))
- mem: add a faster tiered buffer pool; use the experimental [mem.NewBinaryTieredBufferPool](https://pkg.go.dev/google.golang.org/grpc/mem@master#NewBinaryTieredBufferPool) function to create such pools. ([#&#8203;8775](grpc/grpc-go#8775))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi4wIiwidGFyZ2V0QnJhbmNoIjoidjE2LjAvZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13580
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Type: Security A bug or other problem affecting security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants