CVE-2026-101916: @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.14.5 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.13.6
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use @grpc/grpc-js before 1.13.6 or from the affected 1.14.x line before 1.14.5, configure server credentials with requireClientCertificate set to false, and rely on getAuthContext for authentication decisions. @grpc/grpc-js-xds may also be affected when RBAC authentication is enabled in an affected configuration.
What must an attacker be able to do to exploit this?
An attacker must present an unauthorized peer certificate to a server that reaches the affected configuration. Exploitation depends on the application treating the authentication context returned by getAuthContext as proof that the certificate was authorized.
Are deployments that require client certificates affected by the described condition?
The described condition occurs when server credentials set requireClientCertificate to false. The provided information does not identify configurations with requireClientCertificate set to true as affected by this specific issue.
What is the remediation?
Upgrade @grpc/grpc-js to version 1.13.6 or 1.14.5, which contain the fix. Until upgrading, avoid using getAuthContext as authorization evidence in the affected server-credential configuration.