grpc/grpc-js
- < 1.9.16
- >= 1.10.0, < 1.10.12
- >= 1.11.0, < 1.11.4
- >= 1.12.0, < 1.12.7
- >= 1.13.0, < 1.13.5
- >= 1.14.0, < 1.14.4
A denial-of-service vulnerability has been identified in the @grpc/grpc-js package, affecting versions prior to 1.9.16, 1.10.0 through 1.10.12, 1.11.0 through 1.11.4, 1.12.0 through 1.12.7, 1.13.0 through 1.13.5, and 1.14.0 through 1.14.4. The issue arises when a server process created with @grpc/grpc-js encounters an invalid incoming HTTP/2 stream initiation, leading to a crash. This vulnerability impacts all servers using the @grpc/grpc-js package.
Exploitation of this vulnerability causes the server process to crash, disrupting any active connections or services handled by that process.
Users can upgrade to @grpc/grpc-js versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, or 1.14.4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.