Vulnerability GHSA-99f4-grh7-6pcq
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 11, 2026 at 01:27 PM UTC
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3
Summary
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
Details
Impact
An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js
Patches
The following version have fixes for this vulnerability:
- 1.9.16
- 1.10.12
- 1.11.4
- 1.12.7
- 1.13.5
- 1.14.4
Workarounds
There is no workaround.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 hours ago
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-m9gg-hp2v-232j
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-m9gg-hp2v-232j
Low Risk
2 hours ago
@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-f596-whhp-79r4
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-f596-whhp-79r4
High Risk
3 months ago
@grpc/grpc-js: A malformed request can cause a server crash
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-5375-pq7m-f5r2
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-5375-pq7m-f5r2
Medium Risk
2 years ago
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
0.1.0 - 1.8.21 and 1.9.0 - 1.9.14 and 1.10.0 - 1.10.8 GHSA-7v5v-9h63-cj86
0.1.0 - 1.8.21 and 1.9.0 - 1.9.14 and 1.10.0 - 1.10.8 GHSA-7v5v-9h63-cj86
High Risk
5 years ago
Prototype pollution in grpc and @grpc/grpc-js
0.1.0 - 1.1.7 GHSA-pp75-xfpw-37g9
0.1.0 - 1.1.7 GHSA-pp75-xfpw-37g9
Impacted packages
Timeline
Published
3 months ago
June 11, 2026 at 01:27 PM UTC
Fixed (1.14.4)
4 months ago
May 20, 2026 at 05:17 PM UTC
Fixed (1.13.5)
4 months ago
May 20, 2026 at 05:19 PM UTC
Fixed (1.12.7)
4 months ago
May 20, 2026 at 05:19 PM UTC
Fixed (1.11.4)
4 months ago
May 20, 2026 at 05:20 PM UTC
Fixed (1.10.12)
4 months ago
May 20, 2026 at 05:21 PM UTC
Fixed (1.9.16)
4 months ago
May 20, 2026 at 05:23 PM UTC
Last Modified
20 days ago
September 10, 2026 at 03:50 AM UTC