@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.
Update @grpc/grpc-js to 1.9.16; @grpc/grpc-js to 1.10.12; @grpc/grpc-js to 1.11.4; @grpc/grpc-js to 1.12.7; @grpc/grpc-js to 1.13.5; @grpc/grpc-js to 1.14.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scan@grpc/grpc-js: A malformed request can cause a server crash affects @grpc/grpc-js (npm), @grpc/grpc-js (npm), @grpc/grpc-js (npm), @grpc/grpc-js (npm), @grpc/grpc-js (npm), @grpc/grpc-js (npm). Severity is high. @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| @grpc/grpc-jsnpm |
@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.
Update @grpc/grpc-js to 1.9.16; @grpc/grpc-js to 1.10.12; @grpc/grpc-js to 1.11.4; @grpc/grpc-js to 1.12.7; @grpc/grpc-js to 1.13.5; @grpc/grpc-js to 1.14.4 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scan@grpc/grpc-js: A malformed request can cause a server crash affects @grpc/grpc-js (npm), @grpc/grpc-js (npm), @grpc/grpc-js (npm), @grpc/grpc-js (npm), @grpc/grpc-js (npm), @grpc/grpc-js (npm). Severity is high. @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| @grpc/grpc-jsnpm |
| <1.9.16 |
| 1.9.16 |
| @grpc/grpc-jsnpm | >=1.10.0,<1.10.12 | 1.10.12 |
|---|
| @grpc/grpc-jsnpm | >=1.11.0,<1.11.4 | 1.11.4 |
|---|
| @grpc/grpc-jsnpm | >=1.12.0,<1.12.7 | 1.12.7 |
|---|
| @grpc/grpc-jsnpm | >=1.13.0,<1.13.5 | 1.13.5 |
|---|
| @grpc/grpc-jsnpm | >=1.14.0,<1.14.4 | 1.14.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| <1.9.16 |
| 1.9.16 |
| @grpc/grpc-jsnpm | >=1.10.0,<1.10.12 | 1.10.12 |
|---|
| @grpc/grpc-jsnpm | >=1.11.0,<1.11.4 | 1.11.4 |
|---|
| @grpc/grpc-jsnpm | >=1.12.0,<1.12.7 | 1.12.7 |
|---|
| @grpc/grpc-jsnpm | >=1.13.0,<1.13.5 | 1.13.5 |
|---|
| @grpc/grpc-jsnpm | >=1.14.0,<1.14.4 | 1.14.4 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard