Threat Advisory

gRPC-js Flaw Lets Attackers Bypass Authentication Rules

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-101914 with a CVSS score of 6.5 is a CWE-187 and CWE-863 vulnerability affecting @grpc/grpc-js-xds versions < 1.13.1 affecting @grpc/grpc-js-xds versions = 1.14.0 in @grpc/grpc-js that allows attackers to bypass authentication rules by exploiting an exact path match matcher's prefix matching behavior for case-insensitive matches, resulting in improper authentication when using RBAC to apply authentication rules, which can lead to unauthorized access and data exposure.

RECOMMENDATION:

We recommend you to update @grpc/grpc-js-xds to version 1.13.1 or 1.14.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-101914 with a CVSS score of 6.5 is a CWE-187 and CWE-863 vulnerability affecting @grpc/grpc-js-xds versions < 1.13.1 affecting @grpc/grpc-js-xds versions = 1.14.0 in @grpc/grpc-js that allows attackers to bypass authentication rules by exploiting an exact path match matcher's prefix matching behavior for case-insensitive matches, resulting in improper authentication when using RBAC to apply authentication rules, which can lead to unauthorized access and data exposure.

RECOMMENDATION:

We recommend you to update @grpc/grpc-js-xds to version 1.13.1 or 1.14.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu