Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
@grpc/grpc-js @grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages Low Risk 3.7 2 hours ago 2 hours ago
@grpc/grpc-js @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized High Risk 7.4 2 hours ago 2 hours ago
@grpc/grpc-js-xds @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches Medium Risk 6.5 1 day ago 1 day ago
@grpc/grpc-js @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash High Risk 7.5 3 months ago 20 days ago
@grpc/grpc-js @grpc/grpc-js: A malformed request can cause a server crash High Risk 7.5 3 months ago 20 days ago
@grpc/grpc-js @grpc/grpc-js can allocate memory for incoming messages well above configured limits Medium Risk 5.3 2 years ago 20 days ago
@grpc/grpc-js Prototype pollution in grpc and @grpc/grpc-js High Risk 7.5 5 years ago 1 year ago