CVE-2026-101915
3.7 LOWpublic exploit availablePublished 2026-09-28 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status message sent to the client. The thrown error message is transmitted to the client, causing sensitive information disclosure when the message contains sensitive data. This issue is fixed in versions 1.13.6 and 1.14.5.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses
CWE-550
Public exploit & PoC references
- https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea
- https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f
- https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5
- https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4
All references
- https://github.com/grpc/grpc-node/commit/350de32860428cc62473a00bee4035360690ffea
- https://github.com/grpc/grpc-node/commit/7c5c5181159c6ddd292805881ef2cdec29bb475f
- https://github.com/grpc/grpc-node/commit/e8329b122ca99ba10877e990c2f6edd40224fd0d
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.13.6
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5
- https://github.com/grpc/grpc-node/security/advisories/GHSA-f596-whhp-79r4
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.