CVE-2026-48068High· 7.5▾ Twilight@grpc/grpc-js: A malformed request can cause a server crash
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.6%
An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.
The following version have fixes for this vulnerability:
There is no workaround.
@grpc/grpc-js < 1.9.16@grpc/grpc-js >= 1.10.0, < 1.10.12@grpc/grpc-js >= 1.11.0, < 1.11.4@grpc/grpc-js >= 1.12.0, < 1.12.7@grpc/grpc-js >= 1.13.0, < 1.13.5@grpc/grpc-js >= 1.14.0, < 1.14.4Upgrade to a patched release:
@grpc/grpc-js 1.9.16@grpc/grpc-js 1.10.12@grpc/grpc-js 1.11.4@grpc/grpc-js 1.12.7@grpc/grpc-js 1.13.5@grpc/grpc-js 1.14.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48069High· 7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC
GHSA-hrxh-6v49-42gfHighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
CVE-2026-44001High· 8.6vm2 is an open source vm/sandbox for Node.js
CVE-2026-31812Medium· 5.3Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol
CVE-2026-77078High· 7.5multer vulnerable to Denial of Service via crafted multipart field names