CVE-2026-33186
grpc grpc-go, Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined...
- CVSS
- 9.1
- EPSS
- 1.56% 72.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.21