PT-2026-102346 · Npm · @Grpc/Grpc-Js-Xds+1

·

CVE-2026-101916

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @grpc/grpc-js versions prior to 1.13.6 @grpc/grpc-js versions prior to 1.14.5
Description The getAuthContext() function fails to distinguish between authorized and unauthorized peer certificates when server credentials have requireClientCertificate set to false. This can lead to improper authentication if applications rely on the returned authentication context, treating unauthorized certificates as authorized. This condition can also occur in @grpc/grpc-js-xds when Role-Based Access Control (RBAC) authentication is enabled in affected configurations.
Recommendations Update @grpc/grpc-js to version 1.13.6. Update @grpc/grpc-js to version 1.14.5.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101916
GHSA-M9GG-HP2V-232J

Affected Products

@Grpc/Grpc-Js
@Grpc/Grpc-Js-Xds