CVE-2026-101914Medium· 6.5▾ Sunlit@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparis…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@grpc/grpc-js-xds < 1.13.1@grpc/grpc-js-xds = 1.14.0Patched in:
@grpc/grpc-js-xds 1.13.1@grpc/grpc-js-xds 1.14.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84303MediumgRPC-Go is the Go language implementation of gRPC
GHSA-hrxh-6v49-42gfHighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
CVE-2026-101916High· 7.4@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon
CVE-2026-101915Low· 3.7@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC
CVE-2020-3578Medium· 5.3A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and ac…