CVE-2026-101916
ADVISORY - githubSummary
Impact
When server credentials are created with the requireClientCertificate option set to false, getAuthContext does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for @grpc/grpc-js users who use the result of getAuthContext for authentication.
In particular, @grpc/grpc-js-xds can both set the requireClientCertificate option to false and use the return value of getAuthContext for RBAC authentication in some configurations.
Patches
This vulenrability is fixed in 1.13.6 and 1.14.5.
Workarounds
@grpc/grpc-js users using getAuthContext this way can avoid this problem by setting requireClientCertificate to true. @grpc/grpc-js-xds users using RBAC can avoid this by setting the require_client_certificate field to true in the DownstreamTlsContext in the xDS configuration.
Common Weakness Enumeration (CWE)
Improper Certificate Validation
Improper Certificate Validation
Improper Certificate Validation
NIST
2.2
CVSS SCORE
7.4highGitHub
2.2
CVSS SCORE
7.4highRed Hat
2.2
CVSS SCORE
7.4highminimos
MINI-439f-q38w-2j8x
-
minimos
MINI-444w-cjv8-r5mw
-
minimos
MINI-4mg7-wfg3-877r
-
minimos
MINI-5hhr-jfjp-x3jf
-
minimos
MINI-7c44-chvj-q6fv
-
minimos
MINI-7g9j-g343-c24c
-
minimos
MINI-f8w9-6g9h-rqh3
-
minimos
MINI-mqx3-j399-6qcj
-
minimos
MINI-q3qx-5cj8-7g2m
-
minimos
MINI-qwvv-99vw-4532
-