When using RBAC to apply authentication rules, the exact path (method name) matcher applies a prefix match instead of an exact match for case-insensitive matches. As a result, if a service has a method with a name that is a prefix of the name of a different method, and they have different access rules, and case-insensitive matching is used, this bug can cause improper authentication.
// patches
This vulnerability is fixed in 1.13.1 and 1.14.1.
// workarounds
This problem can be avoided by enabling case-sensitive path matching.
Checked 2026-09-29 at 01:11 UTC. The most recent advisory here was published 2026-09-28. Updated continuously from NVD, GHSA, OSV and CNA feeds.