CVE-2026-101916
7.4 HIGHpublic exploit availablePublished 2026-09-28 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-295
Public exploit & PoC references
- https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee
- https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5
- https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j
All references
- https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee
- https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5
- https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100551PoC
- HIGHCVE-2026-100665PoC
- MEDIUMCVE-2026-100701PoC
- HIGHCVE-2026-100835PoC
- MEDIUMCVE-2026-16792
- LOWCVE-2026-18173
- HIGHCVE-2026-40539
- UNSCOREDCVE-2026-63374PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.