HIGH7.5npm
GHSA-5375-pq7m-f5r2· CVE-2026-48068@grpc/grpc-js: A malformed request can cause a server crash
Modified: 9/10/2026
package
pkg:npm/%40grpc/grpc-js
@grpc/grpc-js: A malformed request can cause a server crash
Modified: 9/10/2026
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
Modified: 9/10/2026
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
Modified: 9/10/2026
Prototype pollution in grpc and @grpc/grpc-js
Modified: 1/14/2025