CVE-2026-101914
CVE-2026-101914 is a medium-severity vulnerability with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-187.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 0% (15th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-187
- Published:
- Last modified:
Description
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.
Frequently asked questions
- What is CVE-2026-101914?
- @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.
- How severe is CVE-2026-101914?
- CVE-2026-101914 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity high, and availability none.
- Is CVE-2026-101914 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (15th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-101914?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-101914 published?
- CVE-2026-101914 was published on 2026-09-28 and last updated on 2026-09-30.
References
- https://github.com/grpc/grpc-node/commit/6cf64b596da03f1942a6b168998f0670217a99c4
- https://github.com/grpc/grpc-node/commit/a6c5b31180cc8cea94d0a5ea215ce31a49e0409f
- https://github.com/grpc/grpc-node/commit/f32f3712e44581d8dfc8359bd8d30096662f4c75
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.13.1
- https://github.com/grpc/grpc-node/releases/tag/@grpc/grpc-js-xds%401.14.1
- https://github.com/grpc/grpc-node/security/advisories/GHSA-88h9-xgvx-hvf2
Other CWE-187 vulnerabilities
- CVE-2024-41110 — Critical (CVSS 9.9): Moby is an open-source project created by Docker for software containerization. A security vulnerability has been…
- CVE-2022-31802 — Critical (CVSS 9.8): In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared…
- CVE-2026-87853 — High (CVSS 7.5): A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject…
- CVE-2026-34785 — High (CVSS 7.5): Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines…
- CVE-2026-62750 — Medium (CVSS 6.5): Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an…
- CVE-2026-84376 — Medium (CVSS 6.3): Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path…