CVE-2026-101915Low· 3.7▾ Sunlit@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the stat…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status message sent to the client. The thrown error message is transmitted to the client, causing sensitive information disclosure when the message contains sensitive data. This issue is fixed in versions 1.13.6 and 1.14.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101916High· 7.4@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon
CVE-2026-101914Medium· 6.5@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC
CVE-2026-33186Critical· 9.1gRPC-Go is the Go language implementation of gRPC
CVE-2026-84303MediumgRPC-Go is the Go language implementation of gRPC
CVE-2026-84304HighgRPC-Go is the Go language implementation of gRPC