@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
Published Sep 28, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.
Affected products
-
- Version < 1.13.1StatusaffectedConstraints-
- Version >= 1.14.0, < 1.14.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
@grpc/grpc-js-xds
npm
Introduced 0 Fixed 1.13.1@grpc/grpc-js-xds
npm
Introduced 1.14.0 Fixed 1.14.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @grpc/grpc-js-xds | 0 | 1.13.1 |
| npm | @grpc/grpc-js-xds | 1.14.0 | 1.14.1 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 29, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (7)
- https://github.com/advisories/GHSA-88h9-xgvx-hvf2 Advisory
- https://github.com/grpc/grpc-node/commit/6cf64b596da03f1942a6b168998f0670217a99c4 x_refsource_MISC
- https://github.com/grpc/grpc-node/commit/a6c5b31180cc8cea94d0a5ea215ce31a49e0409f x_refsource_MISC
- https://github.com/grpc/grpc-node/commit/f32f3712e44581d8dfc8359bd8d30096662f4c75 x_refsource_MISC
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.13.1 x_refsource_MISC
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.14.1 x_refsource_MISC
- https://github.com/grpc/grpc-node/security/advisories/GHSA-88h9-xgvx-hvf2 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-88h9-xgvx-hvf2 | Advisory | |
| https://github.com/grpc/grpc-node/commit/6cf64b596da03f1942a6b168998f0670217a99c4 | x_refsource_MISC | |
| https://github.com/grpc/grpc-node/commit/a6c5b31180cc8cea94d0a5ea215ce31a49e0409f | x_refsource_MISC | |
| https://github.com/grpc/grpc-node/commit/f32f3712e44581d8dfc8359bd8d30096662f4c75 | x_refsource_MISC | |
| https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.13.1 | x_refsource_MISC | |
| https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.14.1 | x_refsource_MISC | |
| https://github.com/grpc/grpc-node/security/advisories/GHSA-88h9-xgvx-hvf2 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.