Improper Certificate Validation Affecting @grpc/grpc-js package, versions <1.13.6>=1.14.0 <1.14.5


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.21% (10th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-GRPCGRPCJS-20251010
  • published29 Sept 2026
  • disclosed28 Sept 2026
  • creditSherry Zhou

Introduced: 28 Sep 2026

NewCVE-2026-101916  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade @grpc/grpc-js to version 1.13.6, 1.14.5 or higher.

Overview

@grpc/grpc-js is a gRPC Library for Node

Affected versions of this package are vulnerable to Improper Certificate Validation via getAuthContext() in server-interceptors.ts and the TLS session handling in transport.ts, where the authorized property of a TLS socket is not checked before treating the peer as authenticated. An attacker with an unauthorized or invalid TLS certificate can present it to the server and have it accepted as a valid authenticated peer, bypassing mutual TLS authentication and gaining unauthorized access to confidential data or the ability to perform unauthorized operations.

CVSS Base Scores

version 4.0
version 3.1