← Πίσω στην αναζήτηση CVE

CVE-2026-48069

@grpc/grpc-js

Περιγραφή

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.

CVSS 7.5EPSS 0.617%Κίνδυνος 0.79
Προβολή πηγής
Δημοσίευση
2026-07-14 20:17:05
Επηρεαζόμενες εκδόσεις
<1.9.16,<1.10.12,<1.11.4,<1.12.7,<1.13.5,<1.14.4
Τύπος
Βιβλιοθήκη
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H