{
  "threat_severity" : "Important",
  "public_date" : "2026-06-11T13:27:44Z",
  "bugzilla" : {
    "description" : "grpc-js: @grpc/grpc-js: Client or server crash via malformed compressed message",
    "id" : "2499683",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2499683"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-248",
  "details" : [ "@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.", "A flaw was found in @grpc/grpc-js, a pure JavaScript gRPC client and server library. An invalid incoming compressed message can cause a client or server process to crash. This vulnerability affects all clients and servers that use @grpc/grpc-js, and no workaround is available. An unauthenticated remote attacker can exploit this to cause a denial of service by sending a malformed compressed message over a gRPC connection." ],
  "statement" : "A flaw was found in @grpc/grpc-js. An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js. There is no workaround.",
  "affected_release" : [ {
    "product_name" : "Red Hat Developer Hub 1.10",
    "release_date" : "2026-07-29T00:00:00Z",
    "advisory" : "RHSA-2026:48126",
    "cpe" : "cpe:/a:redhat:rhdh:1.10::el9",
    "package" : "rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1785332825"
  }, {
    "product_name" : "Red Hat Developer Hub 1.10",
    "release_date" : "2026-07-29T00:00:00Z",
    "advisory" : "RHSA-2026:48126",
    "cpe" : "cpe:/a:redhat:rhdh:1.10::el9",
    "package" : "rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki:1785332668"
  }, {
    "product_name" : "Red Hat Developer Hub 1.10",
    "release_date" : "2026-07-29T00:00:00Z",
    "advisory" : "RHSA-2026:48126",
    "cpe" : "cpe:/a:redhat:rhdh:1.10::el9",
    "package" : "rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator:1785332694"
  }, {
    "product_name" : "Red Hat Developer Hub 1.10",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49642",
    "cpe" : "cpe:/a:redhat:rhdh:1.10::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1785411652"
  }, {
    "product_name" : "Red Hat Developer Hub 1.9",
    "release_date" : "2026-08-10T00:00:00Z",
    "advisory" : "RHSA-2026:52768",
    "cpe" : "cpe:/a:redhat:rhdh:1.9::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1785972843"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Build of Podman Desktop",
    "fix_state" : "Fix deferred",
    "package_name" : "grpc-js",
    "cpe" : "cpe:/a:redhat:podman_desktop:1"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Fix deferred",
    "package_name" : "grpc-js",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Fix deferred",
    "package_name" : "grpc-js",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  }, {
    "product_name" : "Self-service automation portal 2",
    "fix_state" : "Fix deferred",
    "package_name" : "grpc-js",
    "cpe" : "cpe:/a:redhat:ansible_portal:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-48069\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-48069\nhttps://github.com/grpc/grpc-node/security/advisories/GHSA-99f4-grh7-6pcq" ],
  "name" : "CVE-2026-48069",
  "mitigation" : {
    "value" : "Upgrade to @grpc/grpc-js 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, or 1.14.4. There is no workaround for this vulnerability.",
    "lang" : "en:us"
  },
  "csaw" : false
}