Количество 47
Количество 47
CVE-2026-33186
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a sec...
CVE-2026-33186
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a sec...
CVE-2026-33186
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a securi
CVE-2026-33186
gRPC-Go has an authorization bypass via missing leading slash in :path
CVE-2026-33186
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1 ...
openSUSE-SU-2026:20924-1
Security update for elemental-system-agent
openSUSE-SU-2026:20921-1
Security update for elemental-toolkit
openSUSE-SU-2026:20920-1
Security update for elemental-register
openSUSE-SU-2026:20856-1
Security update for shadowsocks-v2ray-plugin
openSUSE-SU-2026:20761-1
Security update for google-guest-agent
openSUSE-SU-2026:20603-1
Security update for ignition
openSUSE-SU-2026:20584-1
Security update for v2ray-core
openSUSE-SU-2026:20555-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:2347-1
Security update for google-osconfig-agent
SUSE-SU-2026:2101-1
Security update for google-guest-agent
SUSE-SU-2026:1395-1
Security update for azure-storage-azcopy
SUSE-SU-2026:1314-1
Security update for ignition
SUSE-SU-2026:1195-1
Security update for google-cloud-sap-agent
SUSE-SU-2026:1194-1
Security update for google-cloud-sap-agent
GHSA-p77j-4mvh-x3m3
gRPC-Go has an authorization bypass via missing leading slash in :path
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33186 gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a sec... | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-33186 gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a sec... | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-33186 gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a securi | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-33186 gRPC-Go has an authorization bypass via missing leading slash in :path | 1% Низкий | 3 месяца назад | ||
CVE-2026-33186 gRPC-Go is the Go language implementation of gRPC. Versions prior to 1 ... | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20924-1 Security update for elemental-system-agent | 1% Низкий | 19 дней назад | ||
openSUSE-SU-2026:20921-1 Security update for elemental-toolkit | 1% Низкий | 19 дней назад | ||
openSUSE-SU-2026:20920-1 Security update for elemental-register | 1% Низкий | 19 дней назад | ||
openSUSE-SU-2026:20856-1 Security update for shadowsocks-v2ray-plugin | 1% Низкий | 26 дней назад | ||
openSUSE-SU-2026:20761-1 Security update for google-guest-agent | 1% Низкий | около 1 месяца назад | ||
openSUSE-SU-2026:20603-1 Security update for ignition | 1% Низкий | 2 месяца назад | ||
openSUSE-SU-2026:20584-1 Security update for v2ray-core | 1% Низкий | 2 месяца назад | ||
openSUSE-SU-2026:20555-1 Security update for google-cloud-sap-agent | 1% Низкий | 2 месяца назад | ||
SUSE-SU-2026:2347-1 Security update for google-osconfig-agent | 1% Низкий | 17 дней назад | ||
SUSE-SU-2026:2101-1 Security update for google-guest-agent | 1% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:1395-1 Security update for azure-storage-azcopy | 1% Низкий | 2 месяца назад | ||
SUSE-SU-2026:1314-1 Security update for ignition | 1% Низкий | 2 месяца назад | ||
SUSE-SU-2026:1195-1 Security update for google-cloud-sap-agent | 1% Низкий | 3 месяца назад | ||
SUSE-SU-2026:1194-1 Security update for google-cloud-sap-agent | 1% Низкий | 3 месяца назад | ||
GHSA-p77j-4mvh-x3m3 gRPC-Go has an authorization bypass via missing leading slash in :path | CVSS3: 9.1 | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу