Vulnerability DatabaseCVE-2026-101916

CVE-2026-101916: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-101916 is an improper certificate validation vulnerability in @grpc/grpc-js, the pure JavaScript implementation of gRPC for Node.js. The getAuthContext function fails to distinguish between authorized and unauthorized peer certificates when server credentials have requireClientCertificate set to false, enabling authentication bypass. Affected versions are @grpc/grpc-js < 1.13.6 and >= 1.14.0, < 1.14.5; @grpc/grpc-js-xds is also affected when RBAC authentication is enabled. The vulnerability was published on September 28, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.4 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-295 (Improper Certificate Validation). In the vulnerable code path within BaseServerInterceptingCall.getAuthContext() in server-interceptors.ts, the function retrieves the peer certificate from the TLS socket without first checking socket.authorized — meaning an unverified or self-signed certificate is returned as part of a populated AuthContext object indistinguishable from a verified one. Similarly, transport.ts set authContext based solely on the presence of a TLS socket, not its authorization status. The fix adds an explicit socket.authorized check before populating the auth context, returning an empty object for unauthorized peers (GitHub Advisory, Patch Commit). Exploitation requires a network-accessible gRPC server configured with requireClientCertificate: false and an application that uses getAuthContext output for access control decisions.

Impact

Successful exploitation allows an unauthenticated network attacker to present an invalid or unauthorized client certificate and have it accepted as authorized, effectively bypassing certificate-based mutual TLS authentication. This results in high confidentiality and integrity impact — an attacker could access protected gRPC endpoints, read sensitive data, or perform unauthorized operations as though they were a trusted client. Availability is not directly impacted. The risk is elevated for service mesh deployments using @grpc/grpc-js-xds with RBAC policies, where the authentication bypass could enable lateral movement within a microservices environment (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.208%, reflecting a low near-term exploitation probability. Exploitation requires high attack complexity — specifically, the attacker must be able to initiate a TLS connection to the target server and the server must be configured with requireClientCertificate: false while using getAuthContext for authorization decisions.

Exploitation steps

  1. Reconnaissance: Identify gRPC services running @grpc/grpc-js versions < 1.13.6 or >= 1.14.0, < 1.14.5 that are network-accessible and configured with requireClientCertificate: false in their server credentials.
  2. Prepare a client certificate: Generate a self-signed or otherwise unauthorized TLS client certificate (e.g., using openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes).
  3. Initiate a gRPC connection: Use a gRPC client (e.g., a custom Node.js client or grpcurl) configured with the unauthorized certificate to connect to the target server over TLS.
  4. Trigger authentication context evaluation: Send a gRPC request to a protected endpoint. Because getAuthContext returns a populated AuthContext with the unauthorized certificate (without checking socket.authorized), the server-side application logic treats the connection as authenticated.
  5. Access protected resources: With authentication bypassed, invoke privileged gRPC methods or, in @grpc/grpc-js-xds deployments with RBAC, bypass role-based access controls to access restricted services (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: Unexpected TLS connections to gRPC server ports from unknown or untrusted IP addresses presenting self-signed or unrecognized client certificates; connections where the TLS handshake completes but the client certificate is not issued by a trusted CA.
  • Logs: gRPC server access logs showing successful requests to protected endpoints from clients with unverified certificates; Node.js TLS debug logs (NODE_DEBUG=tls) indicating socket.authorized = false for sessions that proceeded to serve requests.
  • Application Behavior: Unexpected access to RBAC-protected gRPC endpoints in @grpc/grpc-js-xds deployments; authorization audit logs showing access grants without a corresponding valid certificate chain.

Mitigation and workarounds

Upgrade @grpc/grpc-js to version 1.13.6 or 1.14.5 (or later), which fix the issue by returning an empty AuthContext for unauthorized peer certificates (GitHub Release, GitHub Advisory). As a configuration-based workaround, set requireClientCertificate: true in server credentials to ensure only verified certificates are accepted. For @grpc/grpc-js-xds users with RBAC enabled, set the require_client_certificate field to true in the DownstreamTlsContext in the xDS configuration. Upgrading to a patched version is the recommended long-term remediation.

Community reactions

Red Hat tracked the issue as high severity in their Bugzilla system with 29 CC'd users, indicating broad internal concern across product teams (Red Hat Bugzilla). The vulnerability was reported by researcher manqingzhou and patched by maintainer murgatroid99 (GitHub Advisory). No significant public social media discussion or media coverage has been identified beyond standard vulnerability database entries.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management