Vulnerability GHSA-7v5v-9h63-cj86

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
June 10, 2024 at 09:38 PM UTC
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
0.1.0 - 1.8.21 and 1.9.0 - 1.9.14 and 1.10.0 - 1.10.8
0.1.0 - 1.8.21 and 1.9.0 - 1.9.14 and 1.10.0 - 1.10.8

Summary

@grpc/grpc-js can allocate memory for incoming messages well above configured limits

Details

Impact

There are two separate code paths in which memory can be allocated per message in excess of the grpc.max_receive_message_length channel option:

  1. If an incoming message has a size on the wire greater than the configured limit, the entire message is buffered before it is discarded.
  2. If an incoming message has a size within the limit on the wire but decompresses to a size greater than the limit, the entire message is decompressed into memory, and on the server is not discarded.

Patches

This has been patched in versions 1.10.9, 1.9.15, and 1.8.22

Impacted packages

Timeline

Published
2 years ago
June 10, 2024 at 09:38 PM UTC
Fixed (1.10.9)
2 years ago
June 10, 2024 at 05:35 PM UTC
Fixed (1.9.15)
2 years ago
June 10, 2024 at 05:35 PM UTC
Fixed (1.8.22)
2 years ago
June 10, 2024 at 05:36 PM UTC
Last Modified
20 days ago
September 10, 2026 at 03:50 AM UTC