Grpc / Grpc-Node
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-101916 | @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized | HIGH | 7.4 | Sep 28, 2026 |
| CVE-2026-101915 | @grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages | LOW | 3.7 | Sep 28, 2026 |
| CVE-2026-101914 | @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches | MEDIUM | 6.5 | Sep 28, 2026 |
| CVE-2026-48069 | @grpc/grps-js: An incoming malformed compressed message can cause a client or server crash | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-48068 | @grpc/grps-js: A malformed request can cause a server crash | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2024-37168 | @grpc/grpc-js can allocate memory for incoming messages well above configured limits | MEDIUM | 5.3 | Jun 10, 2024 |
Showing 1 to 6 of 6 CVEs