gRPC-Go [v1.72.2] #1

Open
opened 2026-08-06 11:30:51 +00:00 by victor · 0 comments
Member

Installed: v1.72.2
Fixed in: 1.79.3
Severity: 9.1/10
CVE: CVE-2026-33186
Description: gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 :path pseudo-header.

https://github.com/advisories/GHSA-p77j-4mvh-x3m3

Installed: v1.72.2 Fixed in: 1.79.3 Severity: 9.1/10 CVE: CVE-2026-33186 Description: gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. https://github.com/advisories/GHSA-p77j-4mvh-x3m3
victor added this to the v0.1.0 milestone 2026-08-06 11:30:51 +00:00
victor changed title from gRPC-Go to gRPC-Go [v1.72.2] 2026-08-06 11:31:11 +00:00
victor self-assigned this 2026-08-06 11:31:18 +00:00
Sign in to join this conversation.
No milestone
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
MinBZK/DAWO-Fedora-Kinoite#1
No description provided.