Vulnerability GHSA-7v5v-9h63-cj86
Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
June 10, 2024 at 09:38 PM UTC
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
0.1.0 - 1.8.21 and 1.9.0 - 1.9.14 and 1.10.0 - 1.10.8
0.1.0 - 1.8.21 and 1.9.0 - 1.9.14 and 1.10.0 - 1.10.8
Summary
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
Details
Impact
There are two separate code paths in which memory can be allocated per message in excess of the grpc.max_receive_message_length channel option:
- If an incoming message has a size on the wire greater than the configured limit, the entire message is buffered before it is discarded.
- If an incoming message has a size within the limit on the wire but decompresses to a size greater than the limit, the entire message is decompressed into memory, and on the server is not discarded.
Patches
This has been patched in versions 1.10.9, 1.9.15, and 1.8.22
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 hours ago
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-m9gg-hp2v-232j
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-m9gg-hp2v-232j
Low Risk
2 hours ago
@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-f596-whhp-79r4
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-f596-whhp-79r4
High Risk
3 months ago
@grpc/grpc-js: A malformed request can cause a server crash
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-5375-pq7m-f5r2
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-5375-pq7m-f5r2
High Risk
3 months ago
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-99f4-grh7-6pcq
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-99f4-grh7-6pcq
High Risk
5 years ago
Prototype pollution in grpc and @grpc/grpc-js
0.1.0 - 1.1.7 GHSA-pp75-xfpw-37g9
0.1.0 - 1.1.7 GHSA-pp75-xfpw-37g9
Impacted packages
Timeline
Published
2 years ago
June 10, 2024 at 09:38 PM UTC
Fixed (1.10.9)
2 years ago
June 10, 2024 at 05:35 PM UTC
Fixed (1.9.15)
2 years ago
June 10, 2024 at 05:35 PM UTC
Fixed (1.8.22)
2 years ago
June 10, 2024 at 05:36 PM UTC
Last Modified
20 days ago
September 10, 2026 at 03:50 AM UTC