Improper Authentication in gRPC JavaScript Library by Google
CVE-2026-101916
What is CVE-2026-101916?
The @grpc/grpc-js library, which provides core gRPC functionalities in pure JavaScript, has a serious flaw in its authentication process. Specifically, prior to versions 1.13.6 and 1.14.5, the getAuthContext function fails to appropriately differentiate between authorized and unauthorized peer certificates when server settings do not require client certificates. This misconfiguration can lead to scenarios where unauthorized certificates are mistakenly accepted as valid, jeopardizing the entire authentication framework. This vulnerability is particularly concerning when Role-Based Access Control (RBAC) is activated in affected configurations, allowing malicious actors to exploit this flaw. The issue has been rectified in the aforementioned versions. For further technical details and fixes, please refer to the official advisory and release notes.
Affected Version(s)
grpc-node < 1.13.6 < 1.13.6
grpc-node >= 1.14.0, < 1.14.5 < 1.14.0, 1.14.5
