VYPR
High severity7.5GHSA Advisory· Published Jul 14, 2026· Updated Jul 15, 2026

CVE-2026-48069

CVE-2026-48069

Description

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@grpc/grpc-jsnpm
< 1.9.161.9.16
@grpc/grpc-jsnpm
>= 1.10.0, < 1.10.121.10.12
@grpc/grpc-jsnpm
>= 1.11.0, < 1.11.41.11.4
@grpc/grpc-jsnpm
>= 1.12.0, < 1.12.71.12.7
@grpc/grpc-jsnpm
>= 1.13.0, < 1.13.51.13.5
@grpc/grpc-jsnpm
>= 1.14.0, < 1.14.41.14.4

Affected products

35

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.