CVE-2026-33186 is a critical authorization bypass vulnerability in gRPC-Go versions prior to 1.79.3, stemming from improper input validation of the HTTP/2 :path pseudo-header. This flaw allows attackers to bypass path-based authorization interceptors, including the official grpc/authz package, by sending malformed :path headers that omit the mandatory leading slash. The vulnerability specifically impacts gRPC-Go servers utilizing such interceptors with specific "deny" rules for canonical paths and a fallback "allow" rule. Rated 9.1 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), this vulnerability is remotely exploitable with low attack complexity, requiring no privileges or user interaction. A successful exploit could lead to high confidentiality and integrity impacts, allowing unauthorized access to sensitive resources. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community attention with 67 mentions across various platforms, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.79.3CPE matchmatch criteria | cpe:2.3:a:grpc:grpc:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.