---
id: CVE-2026-101915
title: >-
  @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript,
  without a C++ addon
summary: >-
  @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript,
  without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method
  handler throws an uncaught error, the server includes its error message in the
  stat…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-550
vendor: grpc
product: grpc-node
affected:
  - grpc-node < 1.13.6
  - 'grpc-node >= 1.14.0, < 1.14.5'
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T20:17:09.640'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101915'
references:
  - url: >-
      https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea
    label: security-advisories@github.com
  - url: >-
      https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f
    label: security-advisories@github.com
  - url: >-
      https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d
    label: security-advisories@github.com
  - url: 'https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6'
    label: security-advisories@github.com
  - url: 'https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5'
    label: security-advisories@github.com
  - url: 'https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T20:20:05.660Z'
---

## Overview

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status message sent to the client. The thrown error message is transmitted to the client, causing sensitive information disclosure when the message contains sensitive data. This issue is fixed in versions 1.13.6 and 1.14.5.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
