Vulnerability GHSA-88h9-xgvx-hvf2
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 hours ago
September 28, 2026 at 07:43 PM UTC
@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
1.2.0 - 1.13.0 and 1.14.0
1.2.0 - 1.13.0 and 1.14.0
Summary
@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
Details
Impact
When using RBAC to apply authentication rules, the exact path (method name) matcher applies a prefix match instead of an exact match for case-insensitive matches. As a result, if a service has a method with a name that is a prefix of the name of a different method, and they have different access rules, and case-insensitive matching is used, this bug can cause improper authentication.
Patches
This vulnerability is fixed in 1.13.1 and 1.14.1.
Workarounds
This problem can be avoided by enabling case-sensitive path matching.
Impacted packages
Timeline
Published
3 hours ago
September 28, 2026 at 07:43 PM UTC
Fixed (1.14.1)
11 days ago
September 17, 2026 at 07:48 PM UTC
Fixed (1.13.1)
11 days ago
September 17, 2026 at 07:48 PM UTC
Last Modified
3 hours ago
September 28, 2026 at 08:00 PM UTC