CVE-2026-48069: @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js
References
- github.com/advisories/GHSA-99f4-grh7-6pcq
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4
- github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16
- github.com/grpc/grpc-node/security/advisories/GHSA-99f4-grh7-6pcq
- nvd.nist.gov/vuln/detail/CVE-2026-48069
Code Behaviors & Features
Detect and mitigate CVE-2026-48069 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →