CVE-2026-48069: Grpc Grpc-Node

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.

Affected products

  • Grpc Grpc-Node: before 1.9.16 (fixed in 1.9.16); from 1.10.0, before 1.10.12 (fixed in 1.10.12); from 1.11.0, before 1.11.4 (fixed in 1.11.4); from 1.12.0, before 1.12.7 (fixed in 1.12.7); from 1.13.0, before 1.13.5 (fixed in 1.13.5); from 1.14.0, before 1.14.4 (fixed in 1.14.4)

Published 2026-07-14. Last modified 2026-07-15.