Executive brief
@grpc/grpc-js is a Node.js library used to build gRPC services that communicate with other services over the network. The library fails to enforce configured message size limits in two scenarios: when oversized messages arrive on the wire, and when compressed messages decompress beyond the limit. An attacker can send crafted messages to exhaust a server's available memory, causing service denial or crashes.
Technical details
The vulnerability is a memory allocation bypass (CWE-789) in @grpc/grpc-js where the grpc.max_receive_message_length channel option is not properly enforced. Two code paths allow excessive memory allocation: (1) oversized messages are fully buffered before being discarded, and (2) compressed messages are decompressed into memory even if they exceed the limit (and on servers are not discarded afterward). An attacker on the network can send malicious gRPC messages without authentication to trigger unbounded memory allocation. This enables denial-of-service attacks targeting service availability. Patches are available in versions 1.10.9, 1.9.15, and 1.8.22.
Affected products
- Google grpc-js <1.8.22, >=1.9.0 <1.9.15, >=1.10.0 <1.10.9
Timeline
- 2024-06-10: disclosed
- 2024-06-10: patched: Versions 1.10.9, 1.9.15, and 1.8.22 released