CVE Vulnerabilities

CVE-2026-48069

Uncaught Exception

Published: Jul 14, 2026 | Modified: Jul 15, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4, an invalid incoming compressed message can cause a client or server process that uses @grpc/grpc-js to crash. This issue is fixed in versions 1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, and 1.14.4.

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Developer Hub 1.10RedHatrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1785332825*
Red Hat Developer Hub 1.10RedHatrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki:1785332668*
Red Hat Developer Hub 1.10RedHatrhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator:1785332694*

References