๐Ÿ” CVE Alert

CVE-2026-101915

LOW 3.7

@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status message sent to the client. The thrown error message is transmitted to the client, causing sensitive information disclosure when the message contains sensitive data. This issue is fixed in versions 1.13.6 and 1.14.5.

CWE CWE-550
Vendor grpc
Product grpc-node
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for grpc grpc-node

Be the first to know when new low vulnerabilities affecting grpc grpc-node are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

grpc / grpc-node
< 1.13.6 >= 1.14.0, < 1.14.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4 github.com: https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea github.com: https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f github.com: https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d github.com: https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6 github.com: https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5