Skip to content

chore(deps): update dependency @grpc/grpc-js to v1.14.5 [security] - #9506

Merged
shivanee-p merged 1 commit into
googleapis:mainfrom
renovate-bot:renovate/npm-grpc-grpc-js-vulnerability
Oct 7, 2026
Merged

shivanee-p merged 1 commit into
googleapis:mainfrom
renovate-bot:renovate/npm-grpc-grpc-js-vulnerability

Conversation

@renovate-bot

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@grpc/grpc-js (source) 1.14.4 → 1.14.5 age confidence

@​grpc/grpc-js can allocate memory for incoming messages well above configured limits

CVE-2024-37168 / GHSA-7v5v-9h63-cj86

More information

Details

Impact

There are two separate code paths in which memory can be allocated per message in excess of the grpc.max_receive_message_length channel option:

  1. If an incoming message has a size on the wire greater than the configured limit, the entire message is buffered before it is discarded.
  2. If an incoming message has a size within the limit on the wire but decompresses to a size greater than the limit, the entire message is decompressed into memory, and on the server is not discarded.
Patches

This has been patched in versions 1.10.9, 1.9.15, and 1.8.22

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


@​grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

CVE-2026-48069 / GHSA-99f4-grh7-6pcq

More information

Details

Impact

An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @​grpc/grpc-js

Patches

The following version have fixes for this vulnerability:

  • 1.9.16
  • 1.10.12
  • 1.11.4
  • 1.12.7
  • 1.13.5
  • 1.14.4
Workarounds

There is no workaround.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


@​grpc/grpc-js: A malformed request can cause a server crash

CVE-2026-48068 / GHSA-5375-pq7m-f5r2

More information

Details

Impact

An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @​grpc/grpc-js.

Patches

The following version have fixes for this vulnerability:

  • 1.9.16
  • 1.10.12
  • 1.11.4
  • 1.12.7
  • 1.13.5
  • 1.14.4
Workarounds

There is no workaround.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


@​grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages

CVE-2026-101915 / GHSA-f596-whhp-79r4

More information

Details

Impact

If an application method handler crashes, the error message is included in the status message sent to the client. This can leak to the client any sensitive data that may be included in the error message. This impacts anyone using @grpc/grpc-js to run servers.

Patches

This vulnerability is fixed in 1.13.6 and 1.14.5.

Workarounds

This can be avoided by using a top-level error handler in method handlers to strip out sensitive error information.

Severity

  • CVSS Score: 3.7 / 10 (Low)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


@​grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized

CVE-2026-101916 / GHSA-m9gg-hp2v-232j

More information

Details

Impact

When server credentials are created with the requireClientCertificate option set to false, getAuthContext does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for @grpc/grpc-js users who use the result of getAuthContext for authentication.

In particular, @grpc/grpc-js-xds can both set the requireClientCertificate option to false and use the return value of getAuthContext for RBAC authentication in some configurations.

Patches

This vulenrability is fixed in 1.13.6 and 1.14.5.

Workarounds

@grpc/grpc-js users using getAuthContext this way can avoid this problem by setting requireClientCertificate to true. @grpc/grpc-js-xds users using RBAC can avoid this by setting the require_client_certificate field to true in the DownstreamTlsContext in the xDS configuration.

Severity

  • CVSS Score: 7.4 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

grpc/grpc-node (@​grpc/grpc-js)

v1.14.5: @​grpc/grpc-js 1.14.5

Compare Source

  • Fix a bug that caused clients to automatically transmit excessive error details to clients by default (advisory GHSA-f596-whhp-79r4)
  • Fix a bug that caused getAuthContext to return unverified certificates as though they were verified in some configurations (advisory GHSA-m9gg-hp2v-232j)
  • Fix a bug that could cause stale call data to accumulate if a channel failed to connect for a long period of time (#​3078)
  • Fix a bug that could cause call status to be reported with expected fields missing (#​3079)
  • Avoid redundant end() calls on completed HTTP/2 streams (#​3082 contributed by @​olavloite)
  • Unify call numbers and avoid disabled trace allocations (#​3084 contributed by @​olavloite)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot
renovate-bot requested a review from a team as a code owner October 3, 2026 23:19
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@dpebot

dpebot commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

/gcbrun

@github-actions
github-actions Bot requested a review from danieljbruce October 3, 2026 23:19
@shivanee-p
shivanee-p enabled auto-merge (squash) October 7, 2026 18:19
@shivanee-p
shivanee-p merged commit e4d8d24 into googleapis:main Oct 7, 2026
43 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants