@grpc/grpc-js 是一个纯粹用 JavaScript 实现、不依赖 C++ 附加组件的 gRPC 核心功能库。在版本 1.13.6 及 1.14.5 之前,当服务器证书设置中 为 false 时, 方法无法正确区分已认证和未认证的客户端证书。如果应用程序使用该方法返回的身份认证上下文,可能会将未认证的证书误认为已认证,从而导致身份验证逻辑失效。 在受影响的配置中启用 RBAC(基于角色的访问控制)认证时,@grpc/grpc-js-xds 也会受到此问题的影响。该问题已在版本 1.14.5 和 1.13.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101914 | 6.5 MEDIUM | @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for ca |
| CVE-2026-101915 | 3.7 LOW | @grpc/grpc-js: The server transmits some error messages thrown by method handlers to the c |
No comments yet