PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48068 grpc CVE debrief

CVE-2026-48068 is a HIGH severity vulnerability in @grpc/grpc-js. An invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4. The vulnerability affects users of @grpc/grpc-js, especially those who handle HTTP/2 streams. The issue has been publicly disclosed and patched, and users should update to a fixed version as soon as possible.

Vendor
grpc
Product
grpc-node
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-21
Advisory published
2026-07-14
Advisory updated
2026-07-21

Who should care

Users of @grpc/grpc-js, especially those who handle HTTP/2 streams, should be aware of this vulnerability and take steps to mitigate it. This includes updating to a fixed version of the library and validating and sanitizing incoming HTTP/2 streams. Additionally, users should implement additional monitoring and logging to detect potential attacks.

Technical summary

The @grpc/grpc-js library implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4. Users of @grpc/grpc-js should update to a fixed version to prevent exploitation.

Defensive priority

High

Recommended defensive actions

  • Update @grpc/grpc-js to version 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, or 1.14.4 or later
  • Validate and sanitize incoming HTTP/2 streams
  • Implement additional monitoring and logging to detect potential attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-07-14T20:17:05.710Z and was last modified on 2026-07-21T16:17:13.210Z. The NVD entry is currently Awaiting Analysis. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The @grpc/grpc-js library implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T20:17:05.710Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.