Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-37236

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 5.4

Описание

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

A flaw was found in grpc-gateway up to v2.28.0. A remote attacker could exploit an incorrect access control vulnerability by sending a specially crafted POST request that includes the X-HTTP-Method-Override header. The application processes this header without restricting allowed methods, allowing the request method to be rewritten to an arbitrary attacker-supplied value before routing. This bypasses method-based access controls enforced by upstream proxies or Web Application Firewalls (WAFs), potentially leading to unauthorized actions or information disclosure.

Меры по смягчению последствий

To mitigate this issue, configure any upstream proxies or Web Application Firewalls (WAFs) to strip or sanitize the X-HTTP-Method-Override header from incoming requests before they are forwarded to grpc-gateway applications. This prevents the grpc-gateway from processing the malicious header and bypassing access controls.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Affected
Migration Toolkit for Applications 8mta/mta-hub-rhel9Affected
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-plugin-event-sender-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/logic-rhel9-operatorAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-must-gather-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/observatorium-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/prometheus-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform/platform-operator-bundleNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2525631github.com/grpc-ecosystem/grpc-gateway: grpc-gateway: Access control bypass via X-HTTP-Method-Override header

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
16 дней назад

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

CVSS3: 9.8
nvd
16 дней назад

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

msrc
12 дней назад

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

CVSS3: 9.8
debian
16 дней назад

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The ap ...

CVSS3: 9.8
github
16 дней назад

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

5.4 Medium

CVSS3