CVE-2026-101914: @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches

Published Sep 28, 2026
·
Updated

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.

Other sources

Impact When using RBAC to apply authentication rules, the exact path (method name) matcher applies a prefix match instead of an exact match for case-insensitive matches. As a result, if a service has a method with a name that is a prefix of the name of a different method, and they have different access rules, and case-insensitive matching is used, this bug can cause improper authentication.

Patches

This vulnerability is fixed in 1.13.1 and 1.14.1.

Workarounds This problem can be avoided by enabling case-sensitive path matching.

— GitHub

Affected Software

3 affected componentsFixes available
npm/@grpc/grpc-js<1.13.1, >=1.14.0<1.14.1
npm/@grpc/grpc-js-xds=1.14.0
1.14.1
npm/@grpc/grpc-js-xds<1.13.1
1.13.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@grpc/grpc-js-xds to a version that resolves this vulnerability.

    Fixed in 1.14.1
  2. Upgrade

    Upgrade npm/@grpc/grpc-js-xds to a version that resolves this vulnerability.

    Fixed in 1.13.1
  3. Upgrade

    Upgrade @grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.13.1
  4. Upgrade

    Upgrade @grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.14.1
  5. Configuration

    Enable case-sensitive path matching to avoid the incorrect prefix matching behavior.

    @grpc/grpc-js RBAC case-sensitive path matching = enabled

Event History

Sep 28, 2026
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·07:43 PM
Data Sourced
via GitHub·07:43 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to incorrect authorization?

Deployments using @grpc/grpc-js RBAC with exact path matchers configured for case-insensitive matching are affected when one service method name is a prefix of another method name and the two methods have different access rules.

2

What does an attacker need to exploit this issue?

An attacker must be able to send a request for a longer method name that begins with the name of a differently authorized method. No privileges or user interaction are required, but exploitation depends on the affected RBAC matcher configuration and method naming pattern.

3

How can teams identify potentially affected policies before upgrading?

Review case-insensitive exact-path RBAC rules for method names that are prefixes of other exposed method names. Focus on pairs where the shorter and longer methods have different authorization rules, because the longer request may be evaluated against the shorter method's rule.

4

What remediation is available?

Update @grpc/grpc-js to a fixed version: 1.13.1 or 1.14.1. Until updated, avoid case-insensitive exact-path matching for method names with prefix relationships and differing access controls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203