@grpc/grpc-js Denial-of-Service Vulnerability via Invalid HTTP/2 Stream Initiation

Vulnerability

A denial-of-service vulnerability has been identified in the @grpc/grpc-js package, affecting versions prior to 1.9.16, 1.10.0 through 1.10.12, 1.11.0 through 1.11.4, 1.12.0 through 1.12.7, 1.13.0 through 1.13.5, and 1.14.0 through 1.14.4. The issue arises when a server process created with @grpc/grpc-js encounters an invalid incoming HTTP/2 stream initiation, leading to a crash. This vulnerability impacts all servers using the @grpc/grpc-js package.

Impact

Exploitation of this vulnerability causes the server process to crash, disrupting any active connections or services handled by that process.

Remediation

Users can upgrade to @grpc/grpc-js versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, or 1.14.4 to address this vulnerability.

Added: Jul 15, 2026, 5:29 AM
Updated: Jul 15, 2026, 5:29 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
0.0
relevance
9.7
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.