REDHAT-BUG-2499682: High severity npm/@grpc/grpc-js vulnerability
@grpc/grpc-js is a pure JavaScript gRPC client and server library. An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js. There is no workaround. Fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.9.16 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.10.12 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.11.4 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.12.7 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.13.5 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.14.4
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
All servers created using @grpc/grpc-js are affected. The issue is triggered by an invalid incoming HTTP/2 stream initiation.
What is the impact of successful exploitation?
An invalid incoming HTTP/2 stream initiation can cause the @grpc/grpc-js server process to crash, creating a denial-of-service condition.
Is there a mitigation if an upgrade cannot be applied immediately?
No workaround is available. Updating to a fixed version is the stated remediation.
Which versions contain the fix?
The issue is fixed in @grpc/grpc-js versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.