Vulnerability DatabaseCVE-2026-101914

CVE-2026-101914: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-101914 is an incorrect authorization vulnerability in @grpc/grpc-js-xds, the xDS extension for the pure-JavaScript gRPC implementation. When Role-Based Access Control (RBAC) is configured with case-insensitive path matching, the PathExactValueMatcher incorrectly performs a prefix comparison (startsWith) instead of an equality check (===), allowing requests targeting a longer method name to match the access rules of a shorter method name that is a prefix of it. Affected versions are @grpc/grpc-js-xds prior to 1.13.1 and version 1.14.0 (prior to 1.14.1). The vulnerability was disclosed on September 28, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).

Technical details

The root cause is a partial string comparison bug (CWE-187) in packages/grpc-js-xds/src/matcher.ts within the PathExactValueMatcher.apply() method. When caseInsensitive is true, the original code used value.toLowerCase().startsWith(this.targetValue.toLowerCase()) instead of the correct equality check value.toLowerCase() === this.targetValue.toLowerCase(), resulting in incorrect authorization (CWE-863). The fix, applied in commits 6cf64b5, a6c5b31, and f32f371, replaces the startsWith call with a strict equality comparison (GitHub Commit, GitHub Advisory). Exploitation requires a specific service configuration where one method name is a prefix of another, both have different RBAC access rules, and case-insensitive matching is enabled — making the attack complexity high.

Impact

Successful exploitation allows an unauthenticated remote attacker to bypass RBAC authorization controls and invoke gRPC service methods they should not have access to. The primary impact is a high integrity risk — unauthorized modification or invocation of restricted service operations — with a low confidentiality impact if restricted data is returned by the incorrectly matched method. Availability is not directly affected. The scope of impact is limited to services using @grpc/grpc-js-xds with case-insensitive RBAC path matching and overlapping method name prefixes (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, indicating very low current exploitation probability, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory). Exploitation requires a specific and relatively uncommon service configuration (overlapping method name prefixes with differing RBAC rules and case-insensitive matching enabled), which limits practical exploitability.

Exploitation steps

  1. Reconnaissance: Identify gRPC services using @grpc/grpc-js-xds with RBAC policies that have case-insensitive path matching enabled. Use gRPC reflection or service documentation to enumerate available method names.
  2. Identify prefix overlap: Find a pair of method names where one is a prefix of the other (e.g., /MyService/GetUser and /MyService/GetUserAdmin) and they have different access rules — one permissive, one restricted.
  3. Craft the request: Send a gRPC request targeting the longer, restricted method name (e.g., /MyService/GetUserAdmin) without the required credentials or authorization token.
  4. Trigger prefix match: Because the RBAC matcher incorrectly uses startsWith for case-insensitive comparison, the request for /MyService/GetUserAdmin matches the rule for /MyService/GetUser (the shorter, more permissive method), bypassing the intended access control.
  5. Access restricted functionality: The server processes the request under the wrong authorization rule, granting the attacker access to the restricted method's functionality (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: Unexpected gRPC requests to restricted method paths from unauthenticated or low-privilege clients; requests to longer method names that should require elevated privileges arriving without appropriate credentials.
  • Logs: Authorization audit logs showing access grants to restricted methods for principals that should not have access; mismatches between the requested method path and the RBAC rule that was applied.
  • Application Behavior: Successful invocations of high-privilege gRPC methods by clients that only hold permissions for a shorter-named prefix method.

Mitigation and workarounds

Upgrade @grpc/grpc-js-xds to version 1.13.1 or 1.14.1, which contain the one-line fix replacing the startsWith prefix comparison with a strict equality check in the PathExactValueMatcher (GitHub Release 1.13.1, GitHub Advisory). As a workaround for those unable to upgrade immediately, enable case-sensitive path matching in RBAC configuration, which avoids the vulnerable code path entirely. Review service method naming to ensure no method name is a prefix of another if different access rules apply.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-101895HIGH8.7
  • JavaScript logoJavaScript
  • @angular/platform-server
NoYesSep 28, 2026
CVE-2026-55157HIGH8.4
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesSep 28, 2026
CVE-2026-101914MEDIUM6.5
  • JavaScript logoJavaScript
  • @grpc/grpc-js-xds
NoYesSep 28, 2026
GHSA-6vj9-mwq6-2f5vMEDIUM5.9
  • JavaScript logoJavaScript
  • nodemailer
NoYesSep 28, 2026
CVE-2026-55156MEDIUM5.3
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management