---
id: CVE-2026-101916
title: >-
  @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript,
  without a C++ addon
summary: >-
  @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript,
  without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not
  distinguish authorized from unauthorized peer certificates when server
  credentials set…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-295
vendor: grpc
product: grpc-node
affected:
  - grpc-node < 1.13.6
  - 'grpc-node >= 1.14.0, < 1.14.5'
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T21:17:13.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101916'
references:
  - url: >-
      https://github.com/grpc/grpc-node/commit/2a84ec8b01b9db68ed9d2b117a53a81449edb8ee
    label: security-advisories@github.com
  - url: >-
      https://github.com/grpc/grpc-node/commit/b4e0079c6d22a2adedfcac748e0bc083f783bc7c
    label: security-advisories@github.com
  - url: 'https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js%401.14.5'
    label: security-advisories@github.com
  - url: 'https://github.com/grpc/grpc-node/security/advisories/GHSA-m9gg-hp2v-232j'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T21:20:54.777Z'
---

## Overview

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
