REDHAT-BUG-2510313: Medium severity gRPC gRPC vulnerability

Published Aug 3, 2026
·
Updated

Finding The statically-linked gRPC stack is pinned to v1.46.3 (2022) in the Bazel WORKSPACE file, predating multiple HTTP/2 DoS CVEs that are directly reachable on the network listener:

WORKSPACE:116-117 comgithubgrpcgrpc → gRPC 1.46.3 WORKSPACE:129-130 comgoogleprotobuf → protobuf 3.21.12 WORKSPACE:173-176 zlib → 1.3 The MLMD server is a network-facing gRPC listener (FIND-001: no auth), so gRPC-layer DoS CVEs are directly reachable from any pod that can open a TCP connection to :8080.

The Bazel WORKSPACE pins are content-addressed (sha256), so the issue is staleness, not mutability. Renovate is present (.github/renovate.json) but evidently not covering Bazel httparchive entries.

File: WORKSPACE:116-117,129-130,173-176 Repository: red-hat-data-services/ml-metadata Framework: ASVS V14.2.1; OWASP K8s K07 Vulnerable Components; OpenSSF Scorecard Vulnerabilities CWE: CWE-1395 / CWE-1104 CVSS v3.1: 7.5 (High) AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (inherits gRPC HTTP/2 DoS vectors)

RHOAI Mitigation The DSPO-deployed NetworkPolicy restricts who can reach MLMD port 8080 to only KFP v2 driver pods and DSP components. This limits the attack surface but does not eliminate it — a compromise of a KFP driver pod or DSP component could exploit these CVEs to crash the MLMD pod and disrupt all pipeline runs in the namespace.

Impact An in-cluster attacker who can reach the MLMD pod (within the NetworkPolicy allowlist) can crash or resource-exhaust the MLMD pod via known gRPC/HTTP2 frame-handling bugs, disrupting all pipeline runs in the namespace.

Context ml-metadata is planned for removal from the product (several months out). The stale dependency risk remains active until removal is complete.

Remediation Bump WORKSPACE pins: gRPC >= 1.62, protobuf >= 25.x, zlib >= 1.3.1. Extend Renovate configuration to cover Bazel httparchive entries.

Affected Software

3 affected components
gRPC gRPC<1.62
Google Protobuf<25
zlib zlib<1.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade com_github_grpc_grpc to a version that resolves this vulnerability.

    Fixed in 1.62
  2. Upgrade

    Upgrade com_google_protobuf to a version that resolves this vulnerability.

    Fixed in 25.x
  3. Upgrade

    Upgrade zlib to a version that resolves this vulnerability.

    Fixed in 1.3.1
  4. Configuration

    Extend the Renovate configuration (renovate.json) so it covers Bazel WORKSPACE http_archive pins; this ensures staleness is addressed for the content-addressed sha256 pins.

    Renovate Extend configuration to cover Bazel http_archive entries = enabled

Event History

Aug 3, 2026
Data Sourced
via Red Hat·07:43 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2510313?

The severity of REDHAT-BUG-2510313 is classified as medium with a score of 4.

2

What are the risks associated with REDHAT-BUG-2510313?

REDHAT-BUG-2510313 involves vulnerabilities in the statically-linked gRPC stack that could be exploited for DoS attacks.

3

How do I fix REDHAT-BUG-2510313?

To fix REDHAT-BUG-2510313, update the gRPC stack to a version beyond v1.46.3 to mitigate the known vulnerabilities.

4

Which software is affected by REDHAT-BUG-2510313?

The affected software includes gRPC, Google Protobuf, and zlib.

5

What vulnerabilities are related to REDHAT-BUG-2510313?

REDHAT-BUG-2510313 is related to multiple HTTP/2 DoS CVEs that impact earlier versions of the gRPC stack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203