GHSA-88h9-xgvx-hvf2: Medium severity npm/@grpc/grpc-js-xds vulnerability

Published Sep 28, 2026
·
Updated

Impact When using RBAC to apply authentication rules, the exact path (method name) matcher applies a prefix match instead of an exact match for case-insensitive matches. As a result, if a service has a method with a name that is a prefix of the name of a different method, and they have different access rules, and case-insensitive matching is used, this bug can cause improper authentication.

Patches

This vulnerability is fixed in 1.13.1 and 1.14.1.

Workarounds This problem can be avoided by enabling case-sensitive path matching.

Affected Software

2 affected componentsFixes available
npm/@grpc/grpc-js-xds=1.14.0
1.14.1
npm/@grpc/grpc-js-xds<1.13.1
1.13.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@grpc/grpc-js-xds to a version that resolves this vulnerability.

    Fixed in 1.14.1
  2. Upgrade

    Upgrade npm/@grpc/grpc-js-xds to a version that resolves this vulnerability.

    Fixed in 1.13.1
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.13.1
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.14.1
  5. Configuration

    Enable case-sensitive path matching to avoid improper authentication caused by case-insensitive prefix matching.

    case-sensitive path matching = enabled

Event History

Sep 28, 2026
Advisory Published
via GitHub·07:43 PM
Data Sourced
via GitHub·07:43 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected by this issue?

Deployments using RBAC authentication rules with case-insensitive exact path (method name) matching are affected when one service method name is a prefix of another method name and the two methods have different access rules.

2

What does an attacker need to exploit the vulnerability?

An attacker must be able to send a request to a method whose name extends a differently authorized method name. Exploitation depends on the affected service having the relevant prefix-named methods and case-insensitive matching enabled.

3

Is there a mitigation if upgrading is not immediately possible?

Enable case-sensitive path matching. This avoids the incorrect prefix behavior in case-insensitive matching.

4

Which versions contain fixes?

The issue is fixed in versions 1.13.1 and 1.14.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203