Improper Authentication in gRPC JavaScript Library by Google
CVE-2026-101916

7.4HIGH

Key Information:

Vendor

Grpc

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101916?

The @grpc/grpc-js library, which provides core gRPC functionalities in pure JavaScript, has a serious flaw in its authentication process. Specifically, prior to versions 1.13.6 and 1.14.5, the getAuthContext function fails to appropriately differentiate between authorized and unauthorized peer certificates when server settings do not require client certificates. This misconfiguration can lead to scenarios where unauthorized certificates are mistakenly accepted as valid, jeopardizing the entire authentication framework. This vulnerability is particularly concerning when Role-Based Access Control (RBAC) is activated in affected configurations, allowing malicious actors to exploit this flaw. The issue has been rectified in the aforementioned versions. For further technical details and fixes, please refer to the official advisory and release notes.

Affected Version(s)

grpc-node < 1.13.6 < 1.13.6

grpc-node >= 1.14.0, < 1.14.5 < 1.14.0, 1.14.5

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.