
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-101914 is an incorrect authorization vulnerability in @grpc/grpc-js-xds, the xDS extension for the pure-JavaScript gRPC implementation. When Role-Based Access Control (RBAC) is configured with case-insensitive path matching, the PathExactValueMatcher incorrectly performs a prefix comparison (startsWith) instead of an equality check (===), allowing requests targeting a longer method name to match the access rules of a shorter method name that is a prefix of it. Affected versions are @grpc/grpc-js-xds prior to 1.13.1 and version 1.14.0 (prior to 1.14.1). The vulnerability was disclosed on September 28, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is a partial string comparison bug (CWE-187) in packages/grpc-js-xds/src/matcher.ts within the PathExactValueMatcher.apply() method. When caseInsensitive is true, the original code used value.toLowerCase().startsWith(this.targetValue.toLowerCase()) instead of the correct equality check value.toLowerCase() === this.targetValue.toLowerCase(), resulting in incorrect authorization (CWE-863). The fix, applied in commits 6cf64b5, a6c5b31, and f32f371, replaces the startsWith call with a strict equality comparison (GitHub Commit, GitHub Advisory). Exploitation requires a specific service configuration where one method name is a prefix of another, both have different RBAC access rules, and case-insensitive matching is enabled — making the attack complexity high.
Successful exploitation allows an unauthenticated remote attacker to bypass RBAC authorization controls and invoke gRPC service methods they should not have access to. The primary impact is a high integrity risk — unauthorized modification or invocation of restricted service operations — with a low confidentiality impact if restricted data is returned by the incorrectly matched method. Availability is not directly affected. The scope of impact is limited to services using @grpc/grpc-js-xds with case-insensitive RBAC path matching and overlapping method name prefixes (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, indicating very low current exploitation probability, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory). Exploitation requires a specific and relatively uncommon service configuration (overlapping method name prefixes with differing RBAC rules and case-insensitive matching enabled), which limits practical exploitability.
@grpc/grpc-js-xds with RBAC policies that have case-insensitive path matching enabled. Use gRPC reflection or service documentation to enumerate available method names./MyService/GetUser and /MyService/GetUserAdmin) and they have different access rules — one permissive, one restricted./MyService/GetUserAdmin) without the required credentials or authorization token.startsWith for case-insensitive comparison, the request for /MyService/GetUserAdmin matches the rule for /MyService/GetUser (the shorter, more permissive method), bypassing the intended access control.Upgrade @grpc/grpc-js-xds to version 1.13.1 or 1.14.1, which contain the one-line fix replacing the startsWith prefix comparison with a strict equality check in the PathExactValueMatcher (GitHub Release 1.13.1, GitHub Advisory). As a workaround for those unable to upgrade immediately, enable case-sensitive path matching in RBAC configuration, which avoids the vulnerable code path entirely. Review service method naming to ensure no method name is a prefix of another if different access rules apply.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."