{"id":"CVE-2020-7768","details":"The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.","aliases":["GHSA-pp75-xfpw-37g9"],"modified":"2026-08-07T15:14:47.516303Z","published":"2020-11-11T11:15:10.930Z","related":["SNYK-JAVA-ORGWEBJARSNPM-1038819","SNYK-JS-GRPC-598671","SNYK-JS-GRPCGRPCJS-1038818"],"database_specific":{"unresolved_ranges":[{"vendor_product":"grpc:grpc","cpes":["cpe:2.3:a:grpc:grpc:*:*:*:*:*:node.js:*:*"],"extracted_events":[{"fixed":"1.1.8"},{"fixed":"1.1.8"},{"fixed":"1.1.8"},{"fixed":"1.1.8"},{"fixed":"1.1.8"},{"fixed":"1.1.8"},{"fixed":"1.1.8"},{"fixed":"1.1.8"}],"source":"CPE_RANGE"}]},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038819"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-GRPC-598671"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-GRPCGRPCJS-1038818"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/pull/1605"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/pull/1606"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc","events":[{"introduced":"0"},{"fixed":"85e22ef28d55f27e8efb3d5e2e43ca6f59971065"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.24.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*"}}],"versions":["v1.24.1","v1.24.0","v1.24.0-pre2","v1.24.0-pre1","v1.3.4","release-0_9_1-objectivec-0.5.1","release-0_9_0","release-0_6_0","release-0_6","release_test"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7768.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc-java","events":[{"introduced":"0"},{"fixed":"d231db29e89c437d3e3db548da447ecb0aba2edc"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.24.2"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7768.json","vanir_signatures_modified":"2026-08-07T15:14:47Z","vanir_signatures":[{"source":"https://github.com/grpc/grpc-java/commit/d231db29e89c437d3e3db548da447ecb0aba2edc","target":{"file":"core/src/main/java/io/grpc/internal/GrpcUtil.java"},"deprecated":false,"digest":{"line_hashes":["164780015670432881418715345953555497125","263924045991928699568190811530981950895","54460434567064120051909831655786025959","273935924647023699523545983691724561008"],"threshold":0.9},"id":"CVE-2020-7768-26fa6913","signature_type":"Line","signature_version":"v1"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc-node","events":[{"introduced":"0"},{"fixed":"48a6e1cdec33616f1f4c175872a4c342f2e70a8c"}],"database_specific":{"cpe":"cpe:2.3:a:grpc:grpc:*:*:*:*:*:-:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.24.2"}],"source":"CPE_RANGE"}}],"versions":["@grpc/grpc-js@0.5.3","@grpc/proto-loader@0.5.2","@grpc/grpc-js@0.5.0","@grpc/grpc-js@0.5.2","@grpc/grpc-js@0.5.1","grpc-tools@1.8.0","@grpc/grpc-js@0.4.3","@grpc/grpc-js@0.4.2","@grpc/proto-loader@0.5.1","@grpc/grpc-js@0.4.0","@grpc/proto-loader@0.5.0","grpc-tools@1.7.2","@grpc/grpc-js@0.3.6","grpc-tools@1.7.0","@grpc/proto-loader@0.4.0","@grpc/grpc-js@0.3.4","@grpc/grpc-js@0.3.3","@grpc/grpc-js@0.3.1","@grpc/grpc-js@0.3.0","@grpc/proto-loader@0.3.0","@grpc/grpc-js@0.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7768.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}