{"id":"GHSA-m9gg-hp2v-232j","summary":"@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized","details":"### Impact\nWhen server credentials are created with the `requireClientCertificate` option set to `false`, `getAuthContext` does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for `@grpc/grpc-js` users who use the result of `getAuthContext` for authentication.\n\nIn particular, `@grpc/grpc-js-xds` can both set the `requireClientCertificate` option to `false` and use the return value of `getAuthContext` for RBAC authentication in some configurations.\n\n### Patches\n\nThis vulenrability is fixed in 1.13.6 and 1.14.5.\n\n### Workarounds\n`@grpc/grpc-js` users using `getAuthContext` this way can avoid this problem by setting `requireClientCertificate` to `true`. `@grpc/grpc-js-xds` users using RBAC can avoid this by setting the `require_client_certificate` field to `true` in the DownstreamTlsContext in the xDS configuration.","aliases":["CVE-2026-101916"],"modified":"2026-09-30T15:45:30.357039902Z","published":"2026-09-30T15:35:53Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-30T15:35:53Z","nvd_published_at":"2026-09-28T21:17:13Z","cwe_ids":["CWE-295"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101916"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c"},{"type":"PACKAGE","url":"https://github.com/grpc/grpc-node"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5"}],"affected":[{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc/grpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m9gg-hp2v-232j/GHSA-m9gg-hp2v-232j.json"}},{"package":{"name":"@grpc/grpc-js","ecosystem":"npm","purl":"pkg:npm/%40grpc/grpc-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.14.0"},{"fixed":"1.14.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m9gg-hp2v-232j/GHSA-m9gg-hp2v-232j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}