← Scan another repo

github.com/uber-go/zap

@ 5b81b37b81b8

Submitted 8/4/2026, 1:45:39 AM · Status: ok

Risk grade
D
67 / 100
Findings
387
2 critical2 high2 medium2 low379 info0 on CISA KEV0ATT&CK
Showing 387 of 387 findings

Findings

  • gRPC-Go has an authorization bypass via missing leading slash in :path
    grypeCVE-2026-33186EPSS 1.6%
  • google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
    gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omi…
    trivyCVE-2026-33186
  • gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
    grype
  • gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
    Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in: - Authorization Bypass (Fai…
    trivy

This report is public.