JavaScript gRPC Library Vulnerability Exposes Sensitive Information
CVE-2026-101915

3.7LOW

Key Information:

Vendor

Grpc

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101915?

The @grpc/grpc-js library, which provides core gRPC functionality purely in JavaScript, has a vulnerability that arises when an uncaught error is thrown in an application method handler. When this occurs, the error message is included in the status message sent to the client. If the message contains sensitive data, it can lead to unintended disclosure of that information to the client. This issue affects versions prior to 1.13.6 and 1.14.5 and has been addressed in the respective updates.

Affected Version(s)

grpc-node < 1.13.6 < 1.13.6

grpc-node >= 1.14.0, < 1.14.5 < 1.14.0, 1.14.5

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.