@grpc/grpc-js vulnerabilities
CVEs whose affected-version data names the @grpc/grpc-js package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-48069High· 7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
▾ Twilightgrpc · @grpc/grpc-jsEPSS 0.88%via GHSA
CVE-2026-48068High· 7.5@grpc/grpc-js: A malformed request can cause a server crash
@grpc/grpc-js: A malformed request can cause a server crash
▾ Twilightgrpc · @grpc/grpc-jsEPSS 0.62%via GHSA