2 critical2 high2 medium2 low379 info0 on CISA KEV0ATT&CK
Showing 387 of 387 findings
Findings
gRPC-Go has an authorization bypass via missing leading slash in :path
grypeCVE-2026-33186EPSS 1.6%
google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omi…
trivyCVE-2026-33186
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
grype
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:
- Authorization Bypass (Fai…