CVE-2026-101916: @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized

Published Sep 28, 2026
·
Updated

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6.

Affected Software

1 affected component
npm/@grpc/grpc-js<1.13.6, >=1.14.0<1.14.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.14.5
  2. Upgrade

    Upgrade @grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.13.6

Event History

Sep 28, 2026
CVE Published
via MITRE·08:01 PM
Data Sourced
via MITRE·08:01 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Affected deployments use @grpc/grpc-js before 1.13.6 or from the affected 1.14.x line before 1.14.5, configure server credentials with requireClientCertificate set to false, and rely on getAuthContext for authentication decisions. @grpc/grpc-js-xds may also be affected when RBAC authentication is enabled in an affected configuration.

2

What must an attacker be able to do to exploit this?

An attacker must present an unauthorized peer certificate to a server that reaches the affected configuration. Exploitation depends on the application treating the authentication context returned by getAuthContext as proof that the certificate was authorized.

3

Are deployments that require client certificates affected by the described condition?

The described condition occurs when server credentials set requireClientCertificate to false. The provided information does not identify configurations with requireClientCertificate set to true as affected by this specific issue.

4

What is the remediation?

Upgrade @grpc/grpc-js to version 1.13.6 or 1.14.5, which contain the fix. Until upgrading, avoid using getAuthContext as authorization evidence in the affected server-credential configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203