CVE-2026-101914: @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.
Other sources
Impact When using RBAC to apply authentication rules, the exact path (method name) matcher applies a prefix match instead of an exact match for case-insensitive matches. As a result, if a service has a method with a name that is a prefix of the name of a different method, and they have different access rules, and case-insensitive matching is used, this bug can cause improper authentication.
Patches
This vulnerability is fixed in 1.13.1 and 1.14.1.
Workarounds This problem can be avoided by enabling case-sensitive path matching.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@grpc/grpc-js-xdsto a version that resolves this vulnerability.Fixed in 1.14.1 - Upgrade
Upgrade
npm/@grpc/grpc-js-xdsto a version that resolves this vulnerability.Fixed in 1.13.1 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.13.1 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.14.1 - Configuration
Enable case-sensitive path matching to avoid the incorrect prefix matching behavior.
@grpc/grpc-js RBAC case-sensitive path matching = enabled
Event History
Frequently Asked Questions
Which deployments are exposed to incorrect authorization?
Deployments using @grpc/grpc-js RBAC with exact path matchers configured for case-insensitive matching are affected when one service method name is a prefix of another method name and the two methods have different access rules.
What does an attacker need to exploit this issue?
An attacker must be able to send a request for a longer method name that begins with the name of a differently authorized method. No privileges or user interaction are required, but exploitation depends on the affected RBAC matcher configuration and method naming pattern.
How can teams identify potentially affected policies before upgrading?
Review case-insensitive exact-path RBAC rules for method names that are prefixes of other exposed method names. Focus on pairs where the shorter and longer methods have different authorization rules, because the longer request may be evaluated against the shorter method's rule.
What remediation is available?
Update @grpc/grpc-js to a fixed version: 1.13.1 or 1.14.1. Until updated, avoid case-insensitive exact-path matching for method names with prefix relationships and differing access controls.