CVE-2026-48137
Critical · CVSS 9.1NI grpc-device — Untrusted pointer dereference RCE (CWE-822) via crafted protobuf message
- CVSS
- 9.1
- nvd
- EPSS
- 0.50%
- 39th pct
- KEV
- No
- Class
- other
- CWE-822
Description
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. Successful exploitation requires an attacker to supply a specially crafted Moniker protobuf message. This affects NI grpc-device 2.17.0 and prior versions.
Search profile — drives PoC discovery
Symbols grpc-devicesideband streaming APIMonikerprotobufMonikerReadArrayI16MonikerWriteArrayI16BeginSidebandStreamingSidebandStreamingRequestSidebandStreamingResponseInitiateSidebandStream
Keywords CVE-2026-48137GHSA-ww59-ghm9-mm63NI grpc-devicegrpc-device sidebandMoniker protobufuntrusted pointer dereferencegrpc-device RCENI grpc-device exploitgrpc-device PoCCWE-822 grpc-device
Versions: <= 2.17.0
References
Status: enriched · ingested 2026-06-25T18:00:38.000Z · profiled 2026-07-01T18:30:14.000Z