Skip to content

[Aikido] Fix critical issue in google.golang.org/grpc via minor version upgrade from 1.72.1 to 1.79.3 in third-party - #1

Open
aikido-autofix[bot] wants to merge 1 commit into
trunkfrom
fix/aikido-security-update-packages-37937433-cgu2
Open

[Aikido] Fix critical issue in google.golang.org/grpc via minor version upgrade from 1.72.1 to 1.79.3 in third-party#1
aikido-autofix[bot] wants to merge 1 commit into
trunkfrom
fix/aikido-security-update-packages-37937433-cgu2

Conversation

@aikido-autofix

Copy link
Copy Markdown

Upgrade gRPC-Go to fix critical authorization bypass vulnerability caused by improper HTTP/2 :path validation allowing attackers to bypass path-based security policies.

✅ 1 CVE resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-33186
🚨 CRITICAL
[google.golang.org/grpc] Improper HTTP/2 :path validation allows requests without leading slashes to bypass path-based authorization interceptors, enabling attackers to circumvent "deny" rules and access restricted gRPC methods. This authorization bypass affects servers using path-based RBAC policies with fallback "allow" rules.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants