CVE-2026-101914
Received Received - Intake

Authorization Bypass in gRPC JavaScript Library

Vulnerability report for CVE-2026-101914, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
grpc grpc-js to 1.13.1|end_excluding=1.14.1 (exc)
grpc grpc-js to 1.14.0 (exc)
grpc grpc-js-xds to 1.14.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-187 The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the @grpc/grpc-js library, which implements gRPC functionality in JavaScript. Prior to versions 1.13.1 and 1.14.1, the Role-Based Access Control (RBAC) system used a case-insensitive path matcher that performed prefix comparisons instead of exact matches. This means if one service method name was a prefix of another with different access rules, requests for the longer method could incorrectly match the shorter method's rule, leading to improper authorization.

Detection Guidance

To detect this vulnerability, check the installed version of @grpc/grpc-js-xds. If it is below 1.13.1 or 1.14.1, the system is vulnerable. Run: npm list @grpc/grpc-js-xds. If the version is not listed or is outdated, update it immediately.

Impact Analysis

This vulnerability could allow unauthorized access to gRPC services. If an attacker sends a request to a longer method name that shares a prefix with a shorter method, the system might grant access based on the shorter method's rules instead of the intended rules for the longer method. This could lead to data breaches or unauthorized actions depending on the service's configuration.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized access to sensitive data, violating principles of least privilege and data protection. GDPR requires strict access controls and data protection measures, while HIPAA mandates safeguards to ensure only authorized individuals access protected health information. Improper authorization could lead to violations of these regulations.

Mitigation Strategies

Upgrade @grpc/grpc-js-xds to version 1.13.1 or 1.14.1 or later. If upgrading is not possible, enable case-sensitive path matching as a temporary workaround. Verify the fix by testing RBAC rules with methods that have prefix relationships.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101914. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart