CVE-2026-101916 Details
Description
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6.
A vulnerability exists in the @grpc/grpc-js library, specifically in versions prior to 1.13.6 and 1.14.0 through 1.14.5. The issue arises in the getAuthContext function, which fails to properly differentiate between authorized and unauthorized peer certificates when server credentials are configured to not require client certificates. This flaw can lead to improper authentication, as applications may mistakenly treat unauthorized certificates as authorized. The vulnerability is particularly relevant for @grpc/grpc-js-xds users with RBAC authentication enabled, where the flawed getAuthContext behavior can be exploited.
Users of @grpc/grpc-js should upgrade to version 1.13.6 or 1.14.5. @grpc/grpc-js-xds users can set the require_client_certificate field to true in the DownstreamTlsContext of their xDS configuration to mitigate this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee | [email protected] | Source CodeVendor |
| https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c | [email protected] | Source CodeVendor |
| https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5 | [email protected] | Release NotesVendor |
| https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| @grpc/grpc-js | < 1.13.6 (semver) >= 1.14.0, < 1.14.5 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion