@grpc/grpc-js: A malformed request can cause a server crash
Package
Affected versions
< 1.9.16
>= 1.10.0, < 1.10.12
>= 1.11.0, < 1.11.4
>= 1.12.0, < 1.12.7
>= 1.13.0, < 1.13.5
>= 1.14.0, < 1.14.4
Patched versions
1.9.16
1.10.12
1.11.4
1.12.7
1.13.5
1.14.4
Description
Published to the GitHub Advisory Database
Jun 11, 2026
Reviewed
Jun 11, 2026
Last updated
Jun 11, 2026
Impact
An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.
Patches
The following version have fixes for this vulnerability:
Workarounds
There is no workaround.
References