{"id":"CVE-2026-48068","aliases":["GHSA-5375-pq7m-f5r2"],"title":"@grpc/grpc-js: A malformed request can cause a server crash","summary":"@grpc/grpc-js: A malformed request can cause a server crash","severity":"high","cvss":7.5,"cwe":["CWE-248"],"vendor":"grpc","product":"@grpc/grpc-js","ecosystem":"npm","affected":["@grpc/grpc-js < 1.9.16","@grpc/grpc-js >= 1.10.0, < 1.10.12","@grpc/grpc-js >= 1.11.0, < 1.11.4","@grpc/grpc-js >= 1.12.0, < 1.12.7","@grpc/grpc-js >= 1.13.0, < 1.13.5","@grpc/grpc-js >= 1.14.0, < 1.14.4"],"patched":["@grpc/grpc-js 1.9.16","@grpc/grpc-js 1.10.12","@grpc/grpc-js 1.11.4","@grpc/grpc-js 1.12.7","@grpc/grpc-js 1.13.5","@grpc/grpc-js 1.14.4"],"published":"2026-06-11","updated":"2026-06-11","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-5375-pq7m-f5r2","references":[{"url":"https://github.com/grpc/grpc-node/security/advisories/GHSA-5375-pq7m-f5r2"},{"url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12"},{"url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4"},{"url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7"},{"url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5"},{"url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4"},{"url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16"},{"url":"https://github.com/advisories/GHSA-5375-pq7m-f5r2"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-07T15:41:59.314Z","epss":0.00617,"epssPercentile":0.48193,"slug":"CVE-2026-48068","body":"## Overview\n\n### Impact\nAn invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.\n\n### Patches\nThe following version have fixes for this vulnerability:\n\n - 1.9.16\n - 1.10.12\n - 1.11.4\n - 1.12.7\n - 1.13.5\n - 1.14.4\n\n### Workarounds\nThere is no workaround.\n\n## Affected packages\n\n- `@grpc/grpc-js < 1.9.16`\n- `@grpc/grpc-js >= 1.10.0, < 1.10.12`\n- `@grpc/grpc-js >= 1.11.0, < 1.11.4`\n- `@grpc/grpc-js >= 1.12.0, < 1.12.7`\n- `@grpc/grpc-js >= 1.13.0, < 1.13.5`\n- `@grpc/grpc-js >= 1.14.0, < 1.14.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@grpc/grpc-js 1.9.16`\n- `@grpc/grpc-js 1.10.12`\n- `@grpc/grpc-js 1.11.4`\n- `@grpc/grpc-js 1.12.7`\n- `@grpc/grpc-js 1.13.5`\n- `@grpc/grpc-js 1.14.4`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}