{"id":"CVE-2026-48069","aliases":["GHSA-99f4-grh7-6pcq"],"url":"https://o3.security/vulnerability/CVE-2026-48069","summary":"@grpc/grps-js: An incoming malformed compressed message can cause a client or server crash","details":"@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.","published":"2026-07-14T19:42:32.883Z","modified":"2026-08-12T03:51:32.843854218Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00882,"percentile":0.56418,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@grpc/grpc-js","fixedVersion":"1.9.16"},{"ecosystem":"npm","name":"@grpc/grpc-js","fixedVersion":"1.10.12"},{"ecosystem":"npm","name":"@grpc/grpc-js","fixedVersion":"1.11.4"},{"ecosystem":"npm","name":"@grpc/grpc-js","fixedVersion":"1.12.7"},{"ecosystem":"npm","name":"@grpc/grpc-js","fixedVersion":"1.13.5"},{"ecosystem":"npm","name":"@grpc/grpc-js","fixedVersion":"1.14.4"}],"fix":{"url":"https://github.com/grpc/grpc-node/commit/2375eadcc52ca2b1ef55288bcd6355168b02706c","label":"grpc/grpc-node@2375ead"},"references":[{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.10.12"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.11.4"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.12.7"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.13.5"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.14.4"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/%40grpc%2Fgrpc-js%401.9.16"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48069.json"},{"type":"ADVISORY","url":"https://github.com/grpc/grpc-node/security/advisories/GHSA-99f4-grh7-6pcq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48069"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/commit/2375eadcc52ca2b1ef55288bcd6355168b02706c"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/commit/2fe55fd76a8bb59eaab5f39e3552b5f84985a163"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/commit/4091bd902105f8fb655741758aee71418c48b5d5"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/commit/b3f16094473b5c8f38b0955eafa4a19507127346"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/commit/b61c4d65953db85c2ae55b4b3cd98a4259dc87cb"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/commit/b6dcfc3cee9ef390e5869ebea5a8c5ae187720b9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.843854218Z"}}