
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-101916 is an improper certificate validation vulnerability in @grpc/grpc-js, the pure JavaScript implementation of gRPC for Node.js. The getAuthContext function fails to distinguish between authorized and unauthorized peer certificates when server credentials have requireClientCertificate set to false, enabling authentication bypass. Affected versions are @grpc/grpc-js < 1.13.6 and >= 1.14.0, < 1.14.5; @grpc/grpc-js-xds is also affected when RBAC authentication is enabled. The vulnerability was published on September 28, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.4 (High) (GitHub Advisory, Red Hat).
The root cause is classified as CWE-295 (Improper Certificate Validation). In the vulnerable code path within BaseServerInterceptingCall.getAuthContext() in server-interceptors.ts, the function retrieves the peer certificate from the TLS socket without first checking socket.authorized — meaning an unverified or self-signed certificate is returned as part of a populated AuthContext object indistinguishable from a verified one. Similarly, transport.ts set authContext based solely on the presence of a TLS socket, not its authorization status. The fix adds an explicit socket.authorized check before populating the auth context, returning an empty object for unauthorized peers (GitHub Advisory, Patch Commit). Exploitation requires a network-accessible gRPC server configured with requireClientCertificate: false and an application that uses getAuthContext output for access control decisions.
Successful exploitation allows an unauthenticated network attacker to present an invalid or unauthorized client certificate and have it accepted as authorized, effectively bypassing certificate-based mutual TLS authentication. This results in high confidentiality and integrity impact — an attacker could access protected gRPC endpoints, read sensitive data, or perform unauthorized operations as though they were a trusted client. Availability is not directly impacted. The risk is elevated for service mesh deployments using @grpc/grpc-js-xds with RBAC policies, where the authentication bypass could enable lateral movement within a microservices environment (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.208%, reflecting a low near-term exploitation probability. Exploitation requires high attack complexity — specifically, the attacker must be able to initiate a TLS connection to the target server and the server must be configured with requireClientCertificate: false while using getAuthContext for authorization decisions.
@grpc/grpc-js versions < 1.13.6 or >= 1.14.0, < 1.14.5 that are network-accessible and configured with requireClientCertificate: false in their server credentials.openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes).grpcurl) configured with the unauthorized certificate to connect to the target server over TLS.getAuthContext returns a populated AuthContext with the unauthorized certificate (without checking socket.authorized), the server-side application logic treats the connection as authenticated.@grpc/grpc-js-xds deployments with RBAC, bypass role-based access controls to access restricted services (GitHub Advisory, Patch Commit).NODE_DEBUG=tls) indicating socket.authorized = false for sessions that proceeded to serve requests.@grpc/grpc-js-xds deployments; authorization audit logs showing access grants without a corresponding valid certificate chain.Upgrade @grpc/grpc-js to version 1.13.6 or 1.14.5 (or later), which fix the issue by returning an empty AuthContext for unauthorized peer certificates (GitHub Release, GitHub Advisory). As a configuration-based workaround, set requireClientCertificate: true in server credentials to ensure only verified certificates are accepted. For @grpc/grpc-js-xds users with RBAC enabled, set the require_client_certificate field to true in the DownstreamTlsContext in the xDS configuration. Upgrading to a patched version is the recommended long-term remediation.
Red Hat tracked the issue as high severity in their Bugzilla system with 29 CC'd users, indicating broad internal concern across product teams (Red Hat Bugzilla). The vulnerability was reported by researcher manqingzhou and patched by maintainer murgatroid99 (GitHub Advisory). No significant public social media discussion or media coverage has been identified beyond standard vulnerability database entries.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."