{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@grpc/grpc-js-xds--1.13.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:grpc:grpc-js:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-101916"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@grpc/grpc-js (\u003c 1.13.6, \u003e= 1.14.0, \u003c 1.14.5)","@grpc/grpc-js-xds (\u003c 1.13.6)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","grpc","rbac","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["gRPC"],"content_html":"\u003cp\u003eThe @grpc/grpc-js library (CVE-2026-101916) exhibits a flaw in how it handles client certificate verification within the getAuthContext method. When developers configure server credentials with the requireClientCertificate option set to false, the library fails to properly distinguish between authorized and unauthorized client certificates in the returned authentication context. This vulnerability is particularly critical for applications that rely on the output of getAuthContext for Role-Based Access Control (RBAC) decisions. The issue is documented to affect the @grpc/grpc-js-xds integration, where specific configurations of DownstreamTlsContext can inadvertently enable this bypass, potentially allowing unauthenticated or unauthorized clients to gain access to protected resources. Defenders should prioritize updating affected packages to versions 1.13.6 or 1.14.5 to remediate this logic flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for potential authentication bypass in gRPC-based services. If an application utilizes getAuthContext to enforce security policies, unauthorized parties may masquerade as authorized users. The scope of impact includes any infrastructure utilizing @grpc/grpc-js or @grpc/grpc-js-xds for internal or external service-to-service authentication. If exploited, an attacker could gain unauthorized access to backend services protected by RBAC, potentially leading to data exfiltration or unauthorized execution of RPC methods.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate @grpc/grpc-js and @grpc/grpc-js-xds dependencies to version 1.13.6 or 1.14.5 immediately to patch CVE-2026-101916.\u003c/li\u003e\n\u003cli\u003eAudit application code for usage of getAuthContext to ensure it is not relied upon for security-critical RBAC decisions without explicit client certificate verification.\u003c/li\u003e\n\u003cli\u003eFor configurations that cannot be patched immediately, set the requireClientCertificate option to true in the gRPC server credentials.\u003c/li\u003e\n\u003cli\u003eFor @grpc/grpc-js-xds users, set the require_client_certificate field to true within the DownstreamTlsContext in the xDS configuration to enforce certificate validation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T16:27:33Z","date_published":"2026-09-30T16:27:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-grpc-js-auth-bypass/","summary":"The @grpc/grpc-js library contains an authentication bypass vulnerability (CVE-2026-101916) where unauthorized client certificates may be treated as authorized when requireClientCertificate is disabled.","title":"Improper Authentication in @grpc/grpc-js","url":"https://feed.craftedsignal.io/briefs/2026-09-grpc-js-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - @Grpc/Grpc-Js-Xds (\u003c 1.13.6)","version":"https://jsonfeed.org/version/1.1"}