@grpc/grpc-js
npm6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @grpc/grpc-jspage 1 of 1
- CVE-2020-7768HIGHCVSS 7.5EG 7.5fixed in 1.1.82020-11-11
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
- CVE-2024-37168MEDIUMCVSS 5.3EG 5.3fixed in 1.10.9, 1.9.15 or 1.8.22, by version range2024-06-10
@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.10.9, 1.9.15, and 1.8.22, there are two separate code paths in which memory can be allocated per message in excess of th…
- CVE-2026-101915LOWCVSS 3.7EG 3.7fixed in 1.13.6 or 1.14.5, by version range2026-09-28
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status…
- CVE-2026-101916HIGHCVSS 7.4EG 7.4fixed in 1.13.6 or 1.14.5, by version range2026-09-28
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set r…
- CVE-2026-48068HIGHCVSS 7.5EG 7.5fixed in 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5 or 1.14.4, by version range2026-06-11
@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming HTTP/2 stream initiation can cause a server process create…
- CVE-2026-48069HIGHCVSS 7.5EG 7.5fixed in 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5 or 1.14.4, by version range2026-06-11
@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process th…
Check whether @grpc/grpc-js is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @grpc/grpc-js CVEs against the assets you own.
Book a Demo →