CVE-2026-101914: Grpc Grpc-Node
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.
Affected products
- Grpc Grpc-Node: before 1.13.1 (fixed in 1.13.1); from 1.14.0, before 1.14.1 (fixed in 1.14.1)
Published 2026-09-28. Last modified 2026-09-30.