Vulnerability GHSA-99f4-grh7-6pcq

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 11, 2026 at 01:27 PM UTC
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3

Summary

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

Details

Impact

An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js

Patches

The following version have fixes for this vulnerability:

  • 1.9.16
  • 1.10.12
  • 1.11.4
  • 1.12.7
  • 1.13.5
  • 1.14.4

Workarounds

There is no workaround.

Impacted packages

Timeline

Published
3 months ago
June 11, 2026 at 01:27 PM UTC
Fixed (1.14.4)
4 months ago
May 20, 2026 at 05:17 PM UTC
Fixed (1.13.5)
4 months ago
May 20, 2026 at 05:19 PM UTC
Fixed (1.12.7)
4 months ago
May 20, 2026 at 05:19 PM UTC
Fixed (1.11.4)
4 months ago
May 20, 2026 at 05:20 PM UTC
Fixed (1.10.12)
4 months ago
May 20, 2026 at 05:21 PM UTC
Fixed (1.9.16)
4 months ago
May 20, 2026 at 05:23 PM UTC
Last Modified
20 days ago
September 10, 2026 at 03:50 AM UTC