{"id":"CVE-2026-101914","summary":"@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches","details":"@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.","aliases":["GHSA-88h9-xgvx-hvf2"],"modified":"2026-09-29T11:48:16.170994985Z","published":"2026-09-28T19:36:55.746Z","database_specific":{"cwe_ids":["CWE-187","CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101914.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101914.json"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/commit/6cf64b596da03f1942a6b168998f0670217a99c4"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/commit/a6c5b31180cc8cea94d0a5ea215ce31a49e0409f"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/commit/f32f3712e44581d8dfc8359bd8d30096662f4c75"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.13.1"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.14.1"},{"type":"ADVISORY","url":"https://github.com/grpc/grpc-node/security/advisories/GHSA-88h9-xgvx-hvf2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101914"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grpc/grpc-node","events":[{"introduced":"0"},{"fixed":"83acea8513657debe36edefdc87f498ed0ecc035"},{"introduced":"7db315d094b737f105fd7265dd69ab6d2a7bb2a1"},{"fixed":"8ce94a48ce59c2b73ce10a873aa4c55cdf806605"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.13.1"},{"introduced":"1.14.0"},{"fixed":"1.14.1"}],"source":"AFFECTED_FIELD"}}],"versions":["grpc@1.14.0","grpc@1.13.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101914.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"}]}