grpc-node vulnerabilities
CVEs whose affected-version data names the grpc-node package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-101916High· 7.4@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set…
▾ Twilightgrpc · grpc-nodevia NVD
CVE-2026-101915Low· 3.7@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the stat…
▾ Sunlitgrpc · grpc-nodevia NVD