GHSA-m9gg-hp2v-232j: High severity npm/@grpc/grpc-js vulnerability

Published Sep 30, 2026
·
Updated

Impact When server credentials are created with the requireClientCertificate option set to false, getAuthContext does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for @grpc/grpc-js users who use the result of getAuthContext for authentication.

In particular, @grpc/grpc-js-xds can both set the requireClientCertificate option to false and use the return value of getAuthContext for RBAC authentication in some configurations.

Patches

This vulenrability is fixed in 1.13.6 and 1.14.5.

Workarounds @grpc/grpc-js users using getAuthContext this way can avoid this problem by setting requireClientCertificate to true. @grpc/grpc-js-xds users using RBAC can avoid this by setting the requireclientcertificate field to true in the DownstreamTlsContext in the xDS configuration.

Affected Software

2 affected componentsFixes available
npm/@grpc/grpc-js>=1.14.0<1.14.5
1.14.5
npm/@grpc/grpc-js<1.13.6
1.13.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.14.5
  2. Upgrade

    Upgrade npm/@grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.13.6
  3. Upgrade

    Upgrade @grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.13.6
  4. Upgrade

    Upgrade @grpc/grpc-js to a version that resolves this vulnerability.

    Fixed in 1.14.5
  5. Configuration

    Set require_client_certificate to true in the DownstreamTlsContext for @grpc/grpc-js-xds users using RBAC, or set requireClientCertificate to true when @grpc/grpc-js users use getAuthContext for authentication.

    @grpc/grpc-js-xds and @grpc/grpc-js require_client_certificate / requireClientCertificate = true

Event History

Sep 30, 2026
Advisory Published
via GitHub·03:35 PM
Data Sourced
via GitHub·03:35 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments are exposed when server credentials set requireClientCertificate to false and application authentication relies on the return value of getAuthContext. Certain @grpc/grpc-js-xds configurations are also affected when they use RBAC authentication and can set this option to false.

2

What does an attacker need to exploit the issue?

An attacker needs to present an unauthorized client certificate to a server whose authentication decision uses getAuthContext while requireClientCertificate is false. In that configuration, getAuthContext does not distinguish authorized certificates from unauthorized ones.

3

How can this be mitigated if an upgrade cannot be applied immediately?

For @grpc/grpc-js, set requireClientCertificate to true where getAuthContext is used for authentication. For @grpc/grpc-js-xds deployments using RBAC, set require_client_certificate to true in the xDS DownstreamTlsContext configuration.

4

Which versions contain the fix?

The issue is fixed in versions 1.13.6 and 1.14.5.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203