logo

One Character to Rule Them All: How a Missing Slash Bypasses gRPC-Go Security (CVE-2026-33186)

ID: 8aa404af-4996-5b71-bccc-9bb4adf23798

STIX ID: report--8aa404af-4996-5b71-bccc-9bb4adf23798

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-23

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical gRPC-Go vulnerability (CVE-2026-33186, CVSS 9.1) enables authorization bypass when a request path omits the required leading slash; attackers who can send raw HTTP/2 frames can exploit this to bypass path-based RBAC checks. Users should upgrade to v1.79.3 or apply mitigations: add an outermost interceptor to validate FullMethod, enforce strict HTTP/2 path normalization at proxies (Envoy/NGINX), or adopt a default-deny authorization posture.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.