PatchSiren

grpc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH grpc CVE published 2026-07-14

CVE-2026-48068

CVE-2026-48068 is a HIGH severity vulnerability in @grpc/grpc-js. An invalid incoming HTTP/2 stream initiation can cause a server process created using @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4. The vulnerability affects users of @grpc/grpc-js, especially those who handle HTTP/2 streams. The issue has been publicly disclosed and patched, an [truncated]