Authorization Issue in gRPC.js Affects Service Method Access
CVE-2026-101914
6.5MEDIUM
What is CVE-2026-101914?
The @grpc/grpc-js library, which provides a JavaScript implementation of gRPC without using a C++ add-on, contains an authorization flaw prior to versions 1.13.1 and 1.14.1. The role-based access control (RBAC) implementation incorrectly uses prefix comparison for method names when case-insensitive checks are enabled. This can allow a method with a longer name that prefixes another method's name to inadvertently match the shorter method's access rule, potentially leading to unauthorized access to sensitive functions. To mitigate this risk, it is crucial to update to the patched versions 1.13.1 or 1.14.1.
Affected Version(s)
grpc-node < 1.13.1 < 1.13.1
grpc-node >= 1.14.0, < 1.14.1 < 1.14.0, 1.14.1
