@grpc/grpc-js 是一个纯 JavaScript 实现的 gRPC 核心功能库,无需依赖 C++ 扩展。在版本 1.13.1 和 1.14.1 之前,当启用不区分大小写的匹配模式时,RBAC(基于角色的访问控制)使用的路径(方法名)匹配器采用前缀匹配而非精确相等匹配。如果某个服务的方法名是另一个方法名的前缀,且这两个方法配置了不同的访问权限规则,那么针对较长方法名的请求可能会错误地匹配到较短方法名的访问规则,从而导致授权判断错误。该问题已在版本 1.13.1 和 1.14.1 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101916 | 7.4 HIGH | @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certifica |
| CVE-2026-101915 | 3.7 LOW | @grpc/grpc-js: The server transmits some error messages thrown by method handlers to the c |
No comments yet