@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
Published Sep 28, 2026
7.4
HIGHCVSS 3.1
EPSS 0.21%
Description
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6.
Affected products
-
- Version < 1.13.6StatusaffectedConstraints-
- Version >= 1.14.0, < 1.14.5StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat Build of Podman Desktop
rh-podman-desktop
Affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Affected
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Affected
Self-service automation portal 2
ansible-automation-platform/automation-portal
Affected
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Podman Desktop | rh-podman-desktop | Affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/automation-portal | Affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Affected | n/a |
@grpc/grpc-js
npm
Introduced 0 Fixed 1.13.6@grpc/grpc-js
npm
Introduced 1.14.0 Fixed 1.14.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @grpc/grpc-js | 0 | 1.13.6 |
| npm | @grpc/grpc-js | 1.14.0 | 1.14.5 |
Remediation
Red Hat statement
Red Hat rates this vulnerability as Important because an unauthenticated remote client could bypass access control mechanisms when exposed gRPC services evaluate optional peer certificates. The issue manifests when services permit client certificates optionally and downstream authorization logic or role-based access control relies on the resulting peer authentication context. In environments where client certificates are strictly mandated or completely disabled at the transport layer, the condition cannot be triggered. Although successful exploitation requires specific configuration prerequisites, it allows complete circumvention of identity verification across exposed network services.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-101916 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2542678 Issue Tracking
- https://github.com/advisories/GHSA-m9gg-hp2v-232j Advisory
- https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee x_refsource_MISC
- https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c x_refsource_MISC
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5 x_refsource_MISC
- https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-101916
- https://www.cve.org/CVERecord?id=CVE-2026-101916
Change history (0)
No recorded changes yet.