CVE-2026-101915 Details
Description
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status message sent to the client. The thrown error message is transmitted to the client, causing sensitive information disclosure when the message contains sensitive data. This issue is fixed in versions 1.13.6 and 1.14.5.
A vulnerability in @grpc/grpc-js prior to versions 1.13.6 and 1.14.5 allows for the unintentional transmission of sensitive information. When an application method handler throws an uncaught error, the server includes the error message in the status message sent to the client. This can lead to unauthorized disclosure of sensitive data contained in the error message.
Users can upgrade to @grpc/grpc-js versions 1.13.6 or 1.14.5, both of which address this vulnerability. Alternatively, for those unable to upgrade, a workaround involves using a top-level error handler in method handlers to remove sensitive information from error messages before they are sent to the client.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-550 | Server-generated Error Message Containing Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| @grpc/grpc-js | < 1.13.6 (semver) >= 1.14.0, < 1.14.5 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion