Bug 2542678 (CVE-2026-101916)

Summary: CVE-2026-101916 grpc-js: grpc-js: Authentication bypass via improper peer certificate validation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abarbaro, abuckta, alizardo, bbrownin, cdrage, dkuc, dschmidt, gbenhaim, ikhan, jchui, jhe, jlanda, kshier, ktsao, mstipich, nboldt, niyer, oaljalju, orabin, psrna, rbobbitt, rexwhite, rushinde, sdawley, simaishi, stcannon, sthirugn, twaugh, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in grpc-js. In configurations where client certificates are optional, the authentication context lookup fails to distinguish between authorized and unauthorized peer certificates. A remote attacker can exploit this vulnerability by presenting an untrusted certificate, allowing them to bypass authentication mechanisms and access protected services.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-28 20:33:31 UTC
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6.