@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
Package
Affected versions
< 1.9.16
>= 1.10.0, < 1.10.12
>= 1.11.0, < 1.11.4
>= 1.12.0, < 1.12.7
>= 1.13.0, < 1.13.5
>= 1.14.0, < 1.14.4
Patched versions
1.9.16
1.10.12
1.11.4
1.12.7
1.13.5
1.14.4
Description
Published to the GitHub Advisory Database
Jun 11, 2026
Reviewed
Jun 11, 2026
Last updated
Jun 11, 2026
Impact
An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js
Patches
The following version have fixes for this vulnerability:
Workarounds
There is no workaround.
References