@grpc/grpc-js 是一个完全使用 JavaScript(而非 C++ 原生扩展)实现的 gRPC 核心功能库。在版本 1.13.6 和 1.14.5 之前,当应用程序的方法处理程序抛出一个未捕获的错误时,服务端会将该错误的错误消息包含在发送给客户端的状态消息中。这导致错误消息被直接传输给客户端,若该消息中包含敏感数据,则会引发敏感信息泄露漏洞。该问题已在版本 1.13.6 和 1.14.5 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101916 | 7.4 HIGH | @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certifica |
| CVE-2026-101914 | 6.5 MEDIUM | @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for ca |
No comments yet