PT-2026-102334 · Npm · @Grpc/Grpc-Js

·

CVE-2026-101914

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions @grpc/grpc-js versions prior to 1.13.1 @grpc/grpc-js versions prior to 1.14.1
Description When case-insensitive matching is enabled, the Role-Based Access Control (RBAC) exact path matcher performs a prefix comparison instead of an equality comparison for method names. If one service method name is a prefix of another and both have different access rules, a request for the longer method may incorrectly match the rule of the shorter method, leading to improper authorization.
Recommendations Update to version 1.13.1. Update to version 1.14.1. Enable case-sensitive path matching to avoid this issue.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101914
GHSA-88H9-XGVX-HVF2

Affected Products

@Grpc/Grpc-Js