VDB
Sign up
MEDIUM5.3

GHSA-7v5v-9h63-cj86

@grpc/grpc-js can allocate memory for incoming messages well above configured limits

Quick fix

GHSA-7v5v-9h63-cj86 — @grpc/grpc-js: upgrade to the fixed version with the command below.

npm install @grpc/grpc-js@1.10.9

Details

### Impact There are two separate code paths in which memory can be allocated per message in excess of the `grpc.max_receive_message_length` channel option:

1. If an incoming message has a size on the wire greater than the configured limit, the entire message is buffered before it is discarded. 2. If an incoming message has a size within the limit on the wire but decompresses to a size greater than the limit, the entire message is decompressed into memory, and on the server is not discarded.

### Patches

This has been patched in versions 1.10.9, 1.9.15, and 1.8.22

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@grpc/grpc-js
Introduced in: 1.10.0Fixed in: 1.10.9
Fixnpm install @grpc/grpc-js@1.10.9
npm/@grpc/grpc-js
Introduced in: 1.9.0Fixed in: 1.9.15
Fixnpm install @grpc/grpc-js@1.9.15
npm/@grpc/grpc-js
Introduced in: 0Fixed in: 1.8.22
Fixnpm install @grpc/grpc-js@1.8.22

References