OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-101916: @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized

GitHub Advisories · officialPublished Sep 30, 2026Risk 37/100

### Impact When server credentials are created with the `requireClientCertificate` option set to `false`, `getAuthContext` does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for `@grpc/grpc-js` users who use the result of `getAuthContext` for authentication. In particular, `@grpc/grpc-js-xds` can both set the `requireClientCertificate` option to `false` and use the return value of `getAuthContext` for RBAC authentication in some configurations. ### Patches This vulenrability is fixed in 1.13.6 and 1.14.5. ### Workarounds `@grpc/grpc-js` users using `getAuthContext` this way can avoid this problem by setting `requireClientCertificate` to `true`. `@grpc/grpc-js-xds` users using RBAC can avoid this by setting the `require_client_certificate` field to `true` in the DownstreamTlsContext in the xDS configuration.

Upgrade affected packages to a patched version: @grpc/grpc-js 1.13.6, @grpc/grpc-js 1.14.5.

Vendor
Not specified
Product
@grpc/grpc-js
Exploitation
none known
Evidence
official
CVSS
7.4

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source