CVE-2026-48068: @grpc/grpc-js: A malformed request can cause a server crash
An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.
References
- github.com/advisories/GHSA-5375-pq7m-f5r2
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16
- github.com/grpc/grpc-node/security/advisories/GHSA-5375-pq7m-f5r2
- nvd.nist.gov/vuln/detail/CVE-2026-48068
Code Behaviors & Features
Detect and mitigate CVE-2026-48068 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →