Medium · 4.9 Node.js & npm GHSA-m9gg-hp2v-232j CVE-2026-101916 GHSA-f596-whhp-79r4 CVE-2026-101915
Three @grpc/grpc-js Vulnerabilities: Authentication Bypass, Information Disclosure, and RBAC Matching Flaw
Three vulnerabilities in the @grpc/grpc-js Node.js gRPC library affect certificate authorization checks, error message handling, and RBAC path matching. All three are fixed in updated releases; the most severe (CVE-2026-101916) can cause unauthorized peer certificates to be treated as authorized.
AI summary
The GitHub Advisory Database and NVD have published three separate advisories affecting @grpc/grpc-js, the pure-JavaScript implementation of gRPC core functionality, and the related @grpc/grpc-js-xds package. The issues range from an authentication context flaw that can cause unauthorized certificates to be treated as authorized, to a lower-severity information disclosure issue in error handling, and a path-matching flaw affecting RBAC authorization decisions. Fixed versions are available for all three issues.
What happened
Three distinct vulnerabilities were disclosed in @grpc/grpc-js and the related @grpc/grpc-js-xds package. CVE-2026-101916 concerns the getAuthContext function, which does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false; applications relying on the returned authentication context may treat an unauthorized certificate as authorized. CVE-2026-101915 concerns the server including uncaught error messages from method handlers in the status message sent to clients, which can expose sensitive information if the thrown error contains it. CVE-2026-101914 affects the RBAC exact-path matcher, which performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled; if one method name is a prefix of another and the two have different access rules, a request to the longer method name can incorrectly match the shorter method's rule.
Technical cause
CVE-2026-101916 (CWE-295, Improper Certificate Validation) stems from getAuthContext not differentiating between authorized and unauthorized peer certificates in configurations where requireClientCertificate is set to false; @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled. CVE-2026-101915 (CWE-550, Server-generated Error Message Containing Sensitive Information) occurs because uncaught errors thrown by application method handlers have their error message transmitted to the client in the gRPC status message. CVE-2026-101914 (CWE-187, Partial String Comparison) is caused by the RBAC exact-path matcher using a prefix comparison rather than strict equality when case-insensitive matching is enabled.
Why it matters
These vulnerabilities affect authentication and authorization logic directly. CVE-2026-101916 can lead to applications incorrectly trusting a peer certificate as authorized when it should not be, which is particularly relevant where @grpc/grpc-js-xds is used with RBAC authentication enabled. CVE-2026-101914 can cause RBAC authorization checks to apply the wrong access rule to a request, potentially granting access that should have been restricted. CVE-2026-101915 is a lower-severity issue that can leak sensitive information contained in unhandled error messages to clients.
Who is affected
Applications using @grpc/grpc-js are affected by CVE-2026-101916 and CVE-2026-101915. Applications using @grpc/grpc-js-xds, specifically those with RBAC authentication enabled, are affected by CVE-2026-101914 and can also reach the condition described in CVE-2026-101916.
Affected versions
For CVE-2026-101916 and CVE-2026-101915: @grpc/grpc-js versions in the range >= 1.14.0, < 1.14.5 are affected, as are versions prior to 1.13.6 in the 1.13.x line. For CVE-2026-101914: @grpc/grpc-js-xds version 1.14.0 is affected, as are versions prior to 1.13.1 in the 1.13.x line.
Fixes and mitigation
CVE-2026-101916 and CVE-2026-101915 are fixed in @grpc/grpc-js version 1.14.5 and version 1.13.6. CVE-2026-101914 is fixed in @grpc/grpc-js-xds version 1.14.1 and version 1.13.1.
Recommended action
Update @grpc/grpc-js to version 1.14.5 or 1.13.6 depending on your current release line. Update @grpc/grpc-js-xds to version 1.14.1 or 1.13.1 depending on your current release line. Review application code that relies on getAuthContext for authorization decisions, and review method handler error messages for sensitive content that should not be exposed to clients. If RBAC is used with case-insensitive matching and overlapping method name prefixes, verify that access rules are applied correctly after upgrading.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Why this score
CVE-2026-101916 has a patchwire score of 4.9, driven primarily by its CVSS base score of 7.4 (network-exploitable, high confidentiality and integrity impact, no privileges or user interaction required), with no known exploitation or public exploit code. CVE-2026-101914 scores 4.4, based on a CVSS base score of 6.5 reflecting its integrity impact on authorization decisions. CVE-2026-101915 scores 2.8, reflecting a lower CVSS base score of 3.7 and limited confidentiality impact. None of the three vulnerabilities have confirmed exploitation in the wild, known public exploit code, or EPSS data beyond low percentile scores where available.
Affected versions
- @grpc/grpc-js >= 1.14.0, < 1.14.5
- vulnerable
- ≥ 1.13.6
- patched
- ≥ 1.14.5
- patched
- @grpc/grpc-js >= 1.14.0, < 1.14.5
- vulnerable
- ≥ 1.13.6
- patched
- ≥ 1.14.5
- patched
- @grpc/grpc-js-xds = 1.14.0
- vulnerable
- ≥ 1.13.1
- patched
- ≥ 1.14.1
- patched
Reported fixes
CVE-2026-101916 and CVE-2026-101915 are fixed in @grpc/grpc-js version 1.14.5 and version 1.13.6. CVE-2026-101914 is fixed in @grpc/grpc-js-xds version 1.14.1 and version 1.13.1.
How this was built
6 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
-
GitHub Advisory Database database
-
NVD (NIST) database
-
NVD (NIST) database
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email