VYPR
High severityGHSA Advisory· Published Jun 11, 2026· Updated Jun 11, 2026

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

CVE-2026-48069

Description

Impact

An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js

Patches

The following version have fixes for this vulnerability:

  • 1.9.16
  • 1.10.12
  • 1.11.4
  • 1.12.7
  • 1.13.5
  • 1.14.4

Workarounds

There is no workaround.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@grpc/grpc-jsnpm
< 1.9.161.9.16
@grpc/grpc-jsnpm
>= 1.10.0, < 1.10.121.10.12
@grpc/grpc-jsnpm
>= 1.11.0, < 1.11.41.11.4
@grpc/grpc-jsnpm
>= 1.12.0, < 1.12.71.12.7
@grpc/grpc-jsnpm
>= 1.13.0, < 1.13.51.13.5
@grpc/grpc-jsnpm
>= 1.14.0, < 1.14.41.14.4

Affected products

34

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.