{"schema_version":"1.7.5","id":"GHSA-5375-pq7m-f5r2","published":"2026-06-11T13:27:54Z","modified":"2026-06-12T06:14:22.654649104Z","aliases":["CVE-2026-48068"],"related":["CGA-r78v-2m6w-5437"],"summary":"@grpc/grpc-js: A malformed request can cause a server crash","details":"### Impact\nAn invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.\n\n### Patches\nThe following version have fixes for this vulnerability:\n\n - 1.9.16\n - 1.10.12\n - 1.11.4\n - 1.12.7\n - 1.13.5\n - 1.14.4\n\n### Workarounds\nThere is no workaround.","affected":[{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.9.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5375-pq7m-f5r2/GHSA-5375-pq7m-f5r2.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.10.0"},{"fixed":"1.10.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5375-pq7m-f5r2/GHSA-5375-pq7m-f5r2.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.11.0"},{"fixed":"1.11.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5375-pq7m-f5r2/GHSA-5375-pq7m-f5r2.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.12.0"},{"fixed":"1.12.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5375-pq7m-f5r2/GHSA-5375-pq7m-f5r2.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.13.0"},{"fixed":"1.13.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5375-pq7m-f5r2/GHSA-5375-pq7m-f5r2.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.14.0"},{"fixed":"1.14.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5375-pq7m-f5r2/GHSA-5375-pq7m-f5r2.json"}}],"references":[{"type":"WEB","url":"https://github.com/grpc/grpc-node/security/advisories/GHSA-5375-pq7m-f5r2"},{"type":"PACKAGE","url":"https://github.com/grpc/grpc-node"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16"}],"database_specific":{"cwe_ids":["CWE-248"],"github_reviewed":true,"github_reviewed_at":"2026-06-11T13:27:54Z","nvd_published_at":null,"severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}