<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:grpc:grpc-Js:*:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agrpcgrpc-jsnode.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:27:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agrpcgrpc-jsnode.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Authentication in @grpc/grpc-js</title><link>https://feed.craftedsignal.io/briefs/2026-09-grpc-js-auth-bypass/</link><pubDate>Wed, 30 Sep 2026 16:27:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-grpc-js-auth-bypass/</guid><description>The @grpc/grpc-js library contains an authentication bypass vulnerability (CVE-2026-101916) where unauthorized client certificates may be treated as authorized when requireClientCertificate is disabled.</description><content:encoded><![CDATA[<p>The @grpc/grpc-js library (CVE-2026-101916) exhibits a flaw in how it handles client certificate verification within the getAuthContext method. When developers configure server credentials with the requireClientCertificate option set to false, the library fails to properly distinguish between authorized and unauthorized client certificates in the returned authentication context. This vulnerability is particularly critical for applications that rely on the output of getAuthContext for Role-Based Access Control (RBAC) decisions. The issue is documented to affect the @grpc/grpc-js-xds integration, where specific configurations of DownstreamTlsContext can inadvertently enable this bypass, potentially allowing unauthenticated or unauthorized clients to gain access to protected resources. Defenders should prioritize updating affected packages to versions 1.13.6 or 1.14.5 to remediate this logic flaw.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for potential authentication bypass in gRPC-based services. If an application utilizes getAuthContext to enforce security policies, unauthorized parties may masquerade as authorized users. The scope of impact includes any infrastructure utilizing @grpc/grpc-js or @grpc/grpc-js-xds for internal or external service-to-service authentication. If exploited, an attacker could gain unauthorized access to backend services protected by RBAC, potentially leading to data exfiltration or unauthorized execution of RPC methods.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update @grpc/grpc-js and @grpc/grpc-js-xds dependencies to version 1.13.6 or 1.14.5 immediately to patch CVE-2026-101916.</li>
<li>Audit application code for usage of getAuthContext to ensure it is not relied upon for security-critical RBAC decisions without explicit client certificate verification.</li>
<li>For configurations that cannot be patched immediately, set the requireClientCertificate option to true in the gRPC server credentials.</li>
<li>For @grpc/grpc-js-xds users, set the require_client_certificate field to true within the DownstreamTlsContext in the xDS configuration to enforce certificate validation.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>grpc</category><category>rbac</category><category>authentication-bypass</category></item></channel></rss>