CVE-2026-101914
Last modified
CVE-2026-101914 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled.
Description
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| grpc | grpc-node | < 1.13.1; >= 1.14.0, < 1.14.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-101914?
How severe is CVE-2026-101914?
How do I fix CVE-2026-101914?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-101909Axios is a promise-based HTTP client for the browser and Nod…8.3
- CVE-2026-10191A vulnerability was determined in Tenda W12 3.0.0.7(4763). I…8.8
- CVE-2026-101910ip-address is a library for parsing and manipulating IPv4 an…6.9
- CVE-2026-101911ip-address is a library for parsing and manipulating IPv4 an…6.3
- CVE-2026-101912ip-address is a library for parsing and manipulating IPv4 an…6.3
- CVE-2026-101913ip-address is a library for parsing and manipulating IPv4 an…6.3
- CVE-2026-101915@grpc/grpc-js implements the core functionality of gRPC pure…3.7
- CVE-2026-10192A vulnerability was identified in Tenda W12 3.0.0.7(4763). T…8.8
- CVE-2026-10193A security flaw has been discovered in OFCMS up to 1.1.3. Th…6.3
- CVE-2026-10194A weakness has been identified in OFFIS DCMTK 3.7.0. This af…6.3
- CVE-2026-10195The FS-Poster plugin for WordPress is vulnerable to Remote C…8.8
- CVE-2026-10196The Mail Mint – Email Marketing, Newsletter, Email Automatio…9.8
Are you affected by CVE-2026-101914?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
