CPE
The @grpc/grpc-js library contains an authentication bypass vulnerability (CVE-2026-101916) where unauthorized client certificates may be treated as authorized when requireClientCertificate is disabled.