GHSA-f596-whhp-79r4: Low severity npm/@grpc/grpc-js vulnerability

Published Sep 30, 2026
·
Updated

Impact If an application method handler crashes, the error message is included in the status message sent to the client. This can leak to the client any sensitive data that may be included in the error message. This impacts anyone using @grpc/grpc-js to run servers.

Patches This vulnerability is fixed in 1.13.6 and 1.14.5.

Workarounds This can be avoided by using a top-level error handler in method handlers to strip out sensitive error information.

Affected Software

2 affected componentsFixes available
npm/@grpc/grpc-js>=1.14.0<1.14.5
1.14.5
npm/@grpc/grpc-js<1.13.6
1.13.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.14.5
  2. Upgrade

    Upgrade npm/@grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.13.6
  3. Upgrade

    Upgrade @grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.13.6
  4. Upgrade

    Upgrade @grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.14.5
  5. Configuration

    Use a top-level error handler in method handlers to strip sensitive error information from errors returned to clients.

    @grpc/grpc-js server method handlers top-level error handler = strip sensitive error information

Event History

Sep 30, 2026
Advisory Published
via GitHub·03:35 PM
Data Sourced
via GitHub·03:35 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Any application using @grpc/grpc-js to run gRPC servers is impacted. The issue concerns error messages returned when an application method handler crashes.

2

What does an attacker need to do to obtain sensitive information?

An attacker would need to cause an application method handler to crash and receive the resulting status message. Sensitive data is exposed only if it is included in the handler's error message.

3

Are fixed versions available?

Yes. The issue is fixed in @grpc/grpc-js versions 1.13.6 and 1.14.5.

4

What can be done if upgrading is not immediately possible?

Use a top-level error handler in method handlers that strips sensitive information from errors before status messages are sent to clients.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203