logo

Database

Asymmetric denial of service - ReDoS In @grpc/grpc-js

Description

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

Impact

An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js

Patches

The following version have fixes for this vulnerability:

    1.9.16

    1.10.12

    1.11.4

    1.12.7

    1.13.5

    1.14.4

Workarounds

There is no workaround.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions