{"id":"CVE-2026-101914","title":"@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon","summary":"@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparis…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","cwe":["CWE-187","CWE-863"],"vendor":"grpc","product":"@grpc/grpc-js-xds","affected":["@grpc/grpc-js-xds < 1.13.1","@grpc/grpc-js-xds = 1.14.0"],"patched":["@grpc/grpc-js-xds 1.13.1","@grpc/grpc-js-xds 1.14.1"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T20:17:09.453","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101914","references":[{"url":"https://github.com/grpc/grpc-node/commit/6cf64b596da03f1942a6b168998f0670217a99c4","label":"security-advisories@github.com"},{"url":"https://github.com/grpc/grpc-node/commit/a6c5b31180cc8cea94d0a5ea215ce31a49e0409f","label":"security-advisories@github.com"},{"url":"https://github.com/grpc/grpc-node/commit/f32f3712e44581d8dfc8359bd8d30096662f4c75","label":"security-advisories@github.com"},{"url":"https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.13.1","label":"security-advisories@github.com"},{"url":"https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.14.1","label":"security-advisories@github.com"},{"url":"https://github.com/grpc/grpc-node/security/advisories/GHSA-88h9-xgvx-hvf2","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-88h9-xgvx-hvf2"}],"tags":["nvd","ghsa","npm","cve.org"],"aliases":["GHSA-88h9-xgvx-hvf2"],"ecosystem":"npm","ingestedAt":"2026-09-28T20:20:05.659Z","slug":"CVE-2026-101914","body":"## Overview\n\n@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-101914)\n\nAffected packages:\n\n- `@grpc/grpc-js-xds < 1.13.1`\n- `@grpc/grpc-js-xds = 1.14.0`\n\nPatched in:\n\n- `@grpc/grpc-js-xds 1.13.1`\n- `@grpc/grpc-js-xds 1.14.1`\n\nSource: https://github.com/advisories/GHSA-88h9-xgvx-hvf2","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}