JavaScript gRPC Library Vulnerability Exposes Sensitive Information
CVE-2026-101915
3.7LOW
What is CVE-2026-101915?
The @grpc/grpc-js library, which provides core gRPC functionality purely in JavaScript, has a vulnerability that arises when an uncaught error is thrown in an application method handler. When this occurs, the error message is included in the status message sent to the client. If the message contains sensitive data, it can lead to unintended disclosure of that information to the client. This issue affects versions prior to 1.13.6 and 1.14.5 and has been addressed in the respective updates.
Affected Version(s)
grpc-node < 1.13.6 < 1.13.6
grpc-node >= 1.14.0, < 1.14.5 < 1.14.0, 1.14.5
