Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48069

Опубликовано: 11 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.

A flaw was found in @grpc/grpc-js, a pure JavaScript gRPC client and server library. An invalid incoming compressed message can cause a client or server process to crash. This vulnerability affects all clients and servers that use @grpc/grpc-js, and no workaround is available. An unauthenticated remote attacker can exploit this to cause a denial of service by sending a malformed compressed message over a gRPC connection.

Отчет

A flaw was found in @grpc/grpc-js. An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js. There is no workaround.

Меры по смягчению последствий

Upgrade to @grpc/grpc-js 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, or 1.14.4. There is no workaround for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktopgrpc-jsFix deferred
Red Hat Developer Hubgrpc-jsFix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3grpc-jsFix deferred
Red Hat OpenShift Dev Spacesgrpc-jsFix deferred
Self-service automation portal 2grpc-jsFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2499683grpc-js: @grpc/grpc-js: Client or server crash via malformed compressed message

EPSS

Процентиль: 46%
0.00625
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
23 дня назад

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.

CVSS3: 7.5
github
около 2 месяцев назад

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

EPSS

Процентиль: 46%
0.00625
Низкий

7.5 High

CVSS3