VDB
KO
HIGH 7.5

GHSA-5375-pq7m-f5r2

@grpc/grpc-js: A malformed request can cause a server crash

Details

### Impact An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.

### Patches The following version have fixes for this vulnerability:

- 1.9.16 - 1.10.12 - 1.11.4 - 1.12.7 - 1.13.5 - 1.14.4

### Workarounds There is no workaround.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @grpc/grpc-js
Introduced in: 0 Fixed in: 1.9.16
Fix npm install @grpc/grpc-js@1.9.16
npm / @grpc/grpc-js
Introduced in: 1.10.0 Fixed in: 1.10.12
Fix npm install @grpc/grpc-js@1.10.12
npm / @grpc/grpc-js
Introduced in: 1.11.0 Fixed in: 1.11.4
Fix npm install @grpc/grpc-js@1.11.4
npm / @grpc/grpc-js
Introduced in: 1.12.0 Fixed in: 1.12.7
Fix npm install @grpc/grpc-js@1.12.7
npm / @grpc/grpc-js
Introduced in: 1.13.0 Fixed in: 1.13.5
Fix npm install @grpc/grpc-js@1.13.5
npm / @grpc/grpc-js
Introduced in: 1.14.0 Fixed in: 1.14.4
Fix npm install @grpc/grpc-js@1.14.4

References