Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-m9gg-hp2v-232j CVE-2026-101916 GHSA-f596-whhp-79r4 CVE-2026-101915

Three @grpc/grpc-js Vulnerabilities: Authentication Bypass, Information Disclosure, and RBAC Matching Flaw

Three vulnerabilities in the @grpc/grpc-js Node.js gRPC library affect certificate authorization checks, error message handling, and RBAC path matching. All three are fixed in updated releases; the most severe (CVE-2026-101916) can cause unauthorized peer certificates to be treated as authorized.

AI summary

The GitHub Advisory Database and NVD have published three separate advisories affecting @grpc/grpc-js, the pure-JavaScript implementation of gRPC core functionality, and the related @grpc/grpc-js-xds package. The issues range from an authentication context flaw that can cause unauthorized certificates to be treated as authorized, to a lower-severity information disclosure issue in error handling, and a path-matching flaw affecting RBAC authorization decisions. Fixed versions are available for all three issues.

What happened

Three distinct vulnerabilities were disclosed in @grpc/grpc-js and the related @grpc/grpc-js-xds package. CVE-2026-101916 concerns the getAuthContext function, which does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false; applications relying on the returned authentication context may treat an unauthorized certificate as authorized. CVE-2026-101915 concerns the server including uncaught error messages from method handlers in the status message sent to clients, which can expose sensitive information if the thrown error contains it. CVE-2026-101914 affects the RBAC exact-path matcher, which performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled; if one method name is a prefix of another and the two have different access rules, a request to the longer method name can incorrectly match the shorter method's rule.

Technical cause

CVE-2026-101916 (CWE-295, Improper Certificate Validation) stems from getAuthContext not differentiating between authorized and unauthorized peer certificates in configurations where requireClientCertificate is set to false; @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled. CVE-2026-101915 (CWE-550, Server-generated Error Message Containing Sensitive Information) occurs because uncaught errors thrown by application method handlers have their error message transmitted to the client in the gRPC status message. CVE-2026-101914 (CWE-187, Partial String Comparison) is caused by the RBAC exact-path matcher using a prefix comparison rather than strict equality when case-insensitive matching is enabled.

Why it matters

These vulnerabilities affect authentication and authorization logic directly. CVE-2026-101916 can lead to applications incorrectly trusting a peer certificate as authorized when it should not be, which is particularly relevant where @grpc/grpc-js-xds is used with RBAC authentication enabled. CVE-2026-101914 can cause RBAC authorization checks to apply the wrong access rule to a request, potentially granting access that should have been restricted. CVE-2026-101915 is a lower-severity issue that can leak sensitive information contained in unhandled error messages to clients.

Who is affected

Applications using @grpc/grpc-js are affected by CVE-2026-101916 and CVE-2026-101915. Applications using @grpc/grpc-js-xds, specifically those with RBAC authentication enabled, are affected by CVE-2026-101914 and can also reach the condition described in CVE-2026-101916.

Affected versions

For CVE-2026-101916 and CVE-2026-101915: @grpc/grpc-js versions in the range >= 1.14.0, < 1.14.5 are affected, as are versions prior to 1.13.6 in the 1.13.x line. For CVE-2026-101914: @grpc/grpc-js-xds version 1.14.0 is affected, as are versions prior to 1.13.1 in the 1.13.x line.

Fixes and mitigation

CVE-2026-101916 and CVE-2026-101915 are fixed in @grpc/grpc-js version 1.14.5 and version 1.13.6. CVE-2026-101914 is fixed in @grpc/grpc-js-xds version 1.14.1 and version 1.13.1.

Recommended action

Update @grpc/grpc-js to version 1.14.5 or 1.13.6 depending on your current release line. Update @grpc/grpc-js-xds to version 1.14.1 or 1.13.1 depending on your current release line. Review application code that relies on getAuthContext for authorization decisions, and review method handler error messages for sensitive content that should not be exposed to clients. If RBAC is used with case-insensitive matching and overlapping method name prefixes, verify that access rules are applied correctly after upgrading.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.4

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Why this score

CVE-2026-101916 has a patchwire score of 4.9, driven primarily by its CVSS base score of 7.4 (network-exploitable, high confidentiality and integrity impact, no privileges or user interaction required), with no known exploitation or public exploit code. CVE-2026-101914 scores 4.4, based on a CVSS base score of 6.5 reflecting its integrity impact on authorization decisions. CVE-2026-101915 scores 2.8, reflecting a lower CVSS base score of 3.7 and limited confidentiality impact. None of the three vulnerabilities have confirmed exploitation in the wild, known public exploit code, or EPSS data beyond low percentile scores where available.

Affected versions

@grpc/grpc-js >= 1.14.0, < 1.14.5
vulnerable
≥ 1.13.6
patched
≥ 1.14.5
patched
@grpc/grpc-js >= 1.14.0, < 1.14.5
vulnerable
≥ 1.13.6
patched
≥ 1.14.5
patched
@grpc/grpc-js-xds = 1.14.0
vulnerable
≥ 1.13.1
patched
≥ 1.14.1
patched

Reported fixes

CVE-2026-101916 and CVE-2026-101915 are fixed in @grpc/grpc-js version 1.14.5 and version 1.13.6. CVE-2026-101914 is fixed in @grpc/grpc-js-xds version 1.14.1 and version 1.13.1.

How this was built

6 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
  • NVD (NIST) database
  • GitHub Advisory Database database
Unified report
Three @grpc/grpc-js Vulnerabilities: Authentication Bypass, Information Disclosure, and RBAC Matching Flaw
1 article · 6 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email