CVE-2026-101914 with a CVSS score of 6.5 is a CWE-187 and CWE-863 vulnerability affecting @grpc/grpc-js-xds versions < 1.13.1 affecting @grpc/grpc-js-xds versions = 1.14.0 in @grpc/grpc-js that allows attackers to bypass authentication rules by exploiting an exact path match matcher's prefix matching behavior for case-insensitive matches, resulting in improper authentication when using RBAC to apply authentication rules, which can lead to unauthorized access and data exposure.
We recommend you to update @grpc/grpc-js-xds to version 1.13.1 or 1.14.1.[/subscribe_to_unlock_form]
CVE-2026-101914 with a CVSS score of 6.5 is a CWE-187 and CWE-863 vulnerability affecting @grpc/grpc-js-xds versions < 1.13.1 affecting @grpc/grpc-js-xds versions = 1.14.0 in @grpc/grpc-js that allows attackers to bypass authentication rules by exploiting an exact path match matcher's prefix matching behavior for case-insensitive matches, resulting in improper authentication when using RBAC to apply authentication rules, which can lead to unauthorized access and data exposure.
We recommend you to update @grpc/grpc-js-xds to version 1.13.1 or 1.14.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]