VDB
Sign up
HIGH7.5

GHSA-99f4-grh7-6pcq

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

Quick fix

GHSA-99f4-grh7-6pcq — @grpc/grpc-js: upgrade to the fixed version with the command below.

npm install @grpc/grpc-js@1.9.16

Details

### Impact An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js

### Patches The following version have fixes for this vulnerability:

- 1.9.16 - 1.10.12 - 1.11.4 - 1.12.7 - 1.13.5 - 1.14.4

### Workarounds There is no workaround.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@grpc/grpc-js
Introduced in: 0Fixed in: 1.9.16
Fixnpm install @grpc/grpc-js@1.9.16
npm/@grpc/grpc-js
Introduced in: 1.10.0Fixed in: 1.10.12
Fixnpm install @grpc/grpc-js@1.10.12
npm/@grpc/grpc-js
Introduced in: 1.11.0Fixed in: 1.11.4
Fixnpm install @grpc/grpc-js@1.11.4
npm/@grpc/grpc-js
Introduced in: 1.12.0Fixed in: 1.12.7
Fixnpm install @grpc/grpc-js@1.12.7
npm/@grpc/grpc-js
Introduced in: 1.13.0Fixed in: 1.13.5
Fixnpm install @grpc/grpc-js@1.13.5
npm/@grpc/grpc-js
Introduced in: 1.14.0Fixed in: 1.14.4
Fixnpm install @grpc/grpc-js@1.14.4

References