Disclosure summary
### Impact When server credentials are created with the `requireClientCertificate` option set to `false`, `getAuthContext` does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for `@grpc/grpc-js` users who use the result of `getAuthContext` for authentication. In particular, `@grpc/grpc-js-xds` can both set the `requireClientCertificate` option to `false` and use the return value of `getAuthContext` for RBAC authentication in some configurations. ### Patches This vulenrability is fixed in 1.13.6 and 1.14.5. ### Workarounds `@grpc/grpc-js` users using `getAuthContext` this way can avoid this problem by setting `requireClientCertificate` to `true`. `@grpc/grpc-js-xds` users using RBAC can avoid this by setting the `require_client_certificate` field to `true` in the DownstreamTlsContext in the xDS configuration.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-m9gg-hp2v-232j
Open original source · Updated Sep 30, 2026
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @grpc/grpc-js | < 1.13.6 | 1.13.6 |
| npm | @grpc/grpc-js | >= 1.14.0, < 1.14.5 | 1.14.5 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T11:35:53-04:00
MODIFIED 2026-09-30T11:35:57-04:00
INGESTED 2026-10-06T11:43:09-04:00