Back

HIGH

@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized

Published Sep 28, 2026

Description

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6.

Affected products

Remediation

Red Hat statement

Red Hat rates this vulnerability as Important because an unauthenticated remote client could bypass access control mechanisms when exposed gRPC services evaluate optional peer certificates. The issue manifests when services permit client certificates optionally and downstream authorization logic or role-based access control relies on the resulting peer authentication context. In environments where client certificates are strictly mandated or completely disabled at the transport layer, the condition cannot be triggered. Although successful exploitation requires specific configuration prerequisites, it allows complete circumvention of identity verification across exposed network services.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 28, 2026
Updated Oct 1, 2026
Reserved Sep 28, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Received
Modified Sep 28, 2026
Red Hat
Severity Important
Public date Sep 28, 2026
GHSA-M9GG-HP2V-232J