CVE-2026-48069High· 7.5▾ Twilight@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.6%
0.6% → 0.9%
An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js
The following version have fixes for this vulnerability:
There is no workaround.
@grpc/grpc-js < 1.9.16@grpc/grpc-js >= 1.10.0, < 1.10.12@grpc/grpc-js >= 1.11.0, < 1.11.4@grpc/grpc-js >= 1.12.0, < 1.12.7@grpc/grpc-js >= 1.13.0, < 1.13.5@grpc/grpc-js >= 1.14.0, < 1.14.4Upgrade to a patched release:
@grpc/grpc-js 1.9.16@grpc/grpc-js 1.10.12@grpc/grpc-js 1.11.4@grpc/grpc-js 1.12.7@grpc/grpc-js 1.13.5@grpc/grpc-js 1.14.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48068High· 7.5@grpc/grpc-js: A malformed request can cause a server crash
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC
CVE-2026-84304HighgRPC-Go is the Go language implementation of gRPC
GHSA-hrxh-6v49-42gfHighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
CVE-2026-48038Medium· 5.3joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
CVE-2026-65410High· 7.5The issue was addressed with improved checks