For information on gRPC Security Policy and reporting potentional security issues, please see gRPC CVE Process.
Security: grpc/grpc-node
Security
SECURITY.md
-
The server transmits some error messages thrown by method handlers to the client in status messagesGHSA-f596-whhp-79r4 published
Sep 17, 2026 by murgatroid99Low -
The exact path match matcher incorrectly only applies a prefix match for case-insensitive matchesGHSA-88h9-xgvx-hvf2 published
Sep 17, 2026 by murgatroid99Moderate -
In certain configurations, getAuthContext can return unauthorized certificates as though they were authorizedGHSA-m9gg-hp2v-232j published
Sep 17, 2026 by murgatroid99High -
An incoming malformed compressed message can cause a client or server crashGHSA-99f4-grh7-6pcq published
May 20, 2026 by murgatroid99High -
A malformed request can cause a server crashGHSA-5375-pq7m-f5r2 published
May 20, 2026 by murgatroid99High -
@grpc/grpc-js can allocate memory for incoming messages well above configured limitsGHSA-7v5v-9h63-cj86 published
Jun 10, 2024 by murgatroid99Moderate
Learn more about advisories related to grpc/grpc-node in the GitHub Advisory Database