CVE-2026-101915
ADVISORY - githubSummary
Impact
If an application method handler crashes, the error message is included in the status message sent to the client. This can leak to the client any sensitive data that may be included in the error message. This impacts anyone using @grpc/grpc-js to run servers.
Patches
This vulnerability is fixed in 1.13.6 and 1.14.5.
Workarounds
This can be avoided by using a top-level error handler in method handlers to strip out sensitive error information.
Common Weakness Enumeration (CWE)
Server-generated Error Message Containing Sensitive Information
Server-generated Error Message Containing Sensitive Information
NIST
2.2
CVSS SCORE
3.7lowGitHub
2.2
CVSS SCORE
3.7lowminimos
MINI-4jg6-7mmp-64x9
-
minimos
MINI-57rr-gjxc-h4f8
-
minimos
MINI-8cfg-gqc6-fhcj
-
minimos
MINI-985w-82vm-2j62
-
minimos
MINI-c34v-6r6g-pm8r
-
minimos
MINI-f3hf-p7jh-wqw4
-
minimos
MINI-f8rf-gj5w-46w9
-
minimos
MINI-gpr6-7vh7-w695
-
minimos
MINI-h8v5-93w6-7h4x
-
minimos
MINI-rj7h-25wp-vv72
-