One Character to Rule Them All: How a Missing Slash Bypasses gRPC-Go Security (CVE-2026-33186)
ID: 8aa404af-4996-5b71-bccc-9bb4adf23798
STIX ID: report--8aa404af-4996-5b71-bccc-9bb4adf23798
Feed Name: securityonline.info
Threat Score
A critical gRPC-Go vulnerability (CVE-2026-33186, CVSS 9.1) enables authorization bypass when a request path omits the required leading slash; attackers who can send raw HTTP/2 frames can exploit this to bypass path-based RBAC checks. Users should upgrade to v1.79.3 or apply mitigations: add an outermost interceptor to validate FullMethod, enforce strict HTTP/2 path normalization at proxies (Envoy/NGINX), or adopt a default-deny authorization posture.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
