{"schema_version":"1.7.5","id":"GHSA-99f4-grh7-6pcq","published":"2026-06-11T13:27:44Z","modified":"2026-06-12T06:14:22.725733339Z","aliases":["CVE-2026-48069"],"related":["CGA-w7p7-2rq5-8x24"],"summary":"@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash","details":"### Impact\nAn invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js\n\n### Patches\nThe following version have fixes for this vulnerability:\n\n - 1.9.16\n - 1.10.12\n - 1.11.4\n - 1.12.7\n - 1.13.5\n - 1.14.4\n\n### Workarounds\nThere is no workaround.","affected":[{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.9.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-99f4-grh7-6pcq/GHSA-99f4-grh7-6pcq.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.10.0"},{"fixed":"1.10.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-99f4-grh7-6pcq/GHSA-99f4-grh7-6pcq.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.11.0"},{"fixed":"1.11.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-99f4-grh7-6pcq/GHSA-99f4-grh7-6pcq.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.12.0"},{"fixed":"1.12.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-99f4-grh7-6pcq/GHSA-99f4-grh7-6pcq.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.13.0"},{"fixed":"1.13.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-99f4-grh7-6pcq/GHSA-99f4-grh7-6pcq.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc%2Fgrpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.14.0"},{"fixed":"1.14.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-99f4-grh7-6pcq/GHSA-99f4-grh7-6pcq.json"}}],"references":[{"type":"WEB","url":"https://github.com/grpc/grpc-node/security/advisories/GHSA-99f4-grh7-6pcq"},{"type":"PACKAGE","url":"https://github.com/grpc/grpc-node"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16"}],"database_specific":{"cwe_ids":["CWE-248","CWE-400"],"github_reviewed":true,"github_reviewed_at":"2026-06-11T13:27:44Z","nvd_published_at":null,"severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}