CVE-2026-101916 @grpc/grpc-js 认证绕过漏洞
影响未授权客户端证书被误判为已授权,导致身份认证绕过
@grpc/grpc-js 是 gRPC 的纯 JavaScript 实现。在 1.13.6 和 1.14.5 之前的版本中,当服务端凭据将 requireClientCertificate 设为 false 时,getAuthContext 无法区分已授权与未授权的对端证书。使用该认证上下文的应用会把未授权证书当作已授权处理,造成认证不当。
影响范围
@grpc/grpc-js 1.13.6 之前及 1.14.5 之前的版本;@grpc/grpc-js-xds 在启用 RBAC 认证的相关配置下也可触发。
漏洞详情
漏洞属于认证绕过类型,成因是 getAuthContext 在 requireClientCertificate 为 false 时未校验对端证书的授权状态。应用若直接信任该上下文返回的认证信息,就会把未授权证书视为合法身份。@grpc/grpc-js-xds 在启用 RBAC 认证的配置下可达到该触发条件。
利用条件与风险
利用前提是服务端使用 requireClientCertificate=false 且应用依赖 getAuthContext 的返回结果做鉴权,攻击者可持未授权证书冒充合法客户端,实战风险较高。
修复建议
升级至 1.14.5 或 1.13.6 及以上版本;临时缓解可在应用层自行校验对端证书的授权状态,或启用 requireClientCertificate 强制校验客户端证书。
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6.