CVE-2026-101915
@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status message sent to the client. The thrown error message is transmitted to the client, causing sensitive information disclosure when the message contains sensitive data. This issue is fixed in versions 1.13.6 and 1.14.5.
| CWE | CWE-550 |
| Vendor | grpc |
| Product | grpc-node |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for grpc grpc-node
Be the first to know when new low vulnerabilities affecting grpc grpc-node are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
grpc / grpc-node
< 1.13.6 >= 1.14.0, < 1.14.5
References
github.com: https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4 github.com: https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea github.com: https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f github.com: https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d github.com: https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6 github.com: https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5