An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.
The following version have fixes for this vulnerability:
There is no workaround.
{
"github_reviewed": true,
"github_reviewed_at": "2026-06-11T13:27:54Z",
"nvd_published_at": null,
"severity": "HIGH",
"cwe_ids": [
"CWE-248"
]
}