@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
Published Sep 28, 2026
3.7
LOWCVSS 3.1
EPSS 0.25%
Description
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status message sent to the client. The thrown error message is transmitted to the client, causing sensitive information disclosure when the message contains sensitive data. This issue is fixed in versions 1.13.6 and 1.14.5.
Affected products
-
- Version < 1.13.6StatusaffectedConstraints-
- Version >= 1.14.0, < 1.14.5StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
@grpc/grpc-js
npm
Introduced 1.14.0 Fixed 1.14.5@grpc/grpc-js
npm
Introduced 0 Fixed 1.13.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @grpc/grpc-js | 1.14.0 | 1.14.5 |
| npm | @grpc/grpc-js | 0 | 1.13.6 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (8)
- https://github.com/advisories/GHSA-f596-whhp-79r4 Advisory
- https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea x_refsource_MISC
- https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f x_refsource_MISC
- https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d x_refsource_MISC
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6 x_refsource_MISC
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5 x_refsource_MISC
- https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-101915
Change history (0)
No recorded changes yet.