Skip to content

[Aikido] Fix security issue in @grpc/grpc-js via minor version upgrade from 1.14.3 to 1.14.4 in with-thirdweb#36

Merged
yosriady merged 1 commit into
mainfrom
fix/aikido-security-update-packages-50139856-xeda
Jun 16, 2026
Merged

[Aikido] Fix security issue in @grpc/grpc-js via minor version upgrade from 1.14.3 to 1.14.4 in with-thirdweb#36
yosriady merged 1 commit into
mainfrom
fix/aikido-security-update-packages-50139856-xeda

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

Upgrade @grpc/grpc-js to fix HIGH severity DoS vulnerability where invalid compressed messages crash client/server processes.

✅ There are no breaking changes

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-48069
HIGH
[@grpc/grpc-js] An invalid incoming compressed message can cause a client or server process to crash, resulting in a denial of service affecting all users of the library.

View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.

@socket-security

Copy link
Copy Markdown

Dependency limit exceeded — report not shown.

This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report.

Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard.

Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account.

@yosriady yosriady merged commit d21e967 into main Jun 16, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant