Vulnerability GHSA-m9gg-hp2v-232j

High Risk
HIGH RISK
CVSS Score: 7.4
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 hour ago
September 30, 2026 at 03:35 PM UTC
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4

Summary

@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized

Details

Impact

When server credentials are created with the requireClientCertificate option set to false, getAuthContext does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for @grpc/grpc-js users who use the result of getAuthContext for authentication.

In particular, @grpc/grpc-js-xds can both set the requireClientCertificate option to false and use the return value of getAuthContext for RBAC authentication in some configurations.

Patches

This vulenrability is fixed in 1.13.6 and 1.14.5.

Workarounds

@grpc/grpc-js users using getAuthContext this way can avoid this problem by setting requireClientCertificate to true. @grpc/grpc-js-xds users using RBAC can avoid this by setting the require_client_certificate field to true in the DownstreamTlsContext in the xDS configuration.

Impacted packages

Timeline

Published
1 hour ago
September 30, 2026 at 03:35 PM UTC
Fixed (1.13.6)
Unknown
Unknown
Fixed (1.14.5)
Unknown
Unknown
Last Modified
1 hour ago
September 30, 2026 at 03:45 PM UTC