A high-severity flaw tracked as CVE-2026-33186 allows attackers to bypass path-based authorization in gRPC-Go by sending malformed HTTP/2 requests whose :path pseudo-header omits the required leading slash. In affected versions before 1.79.3, the server still routed requests correctly, but authorization components evaluated the non-canonical path value, creating a mismatch that let canonical deny rules fail. The issue affects deployments using google.golang.org/grpc/authz RBAC as well as custom interceptors that rely on info.FullMethod or grpc.Method(ctx) while otherwise permitting requests by default.
Reports say the flaw can also impact products and middleware built on gRPC-Go, including Traefik custom middleware, where policies written for paths such as /InternalService/SensitiveMethod could be bypassed with malformed variants like InternalService/SensitiveMethod. Exploitation requires the ability to send raw HTTP/2 frames directly to a gRPC server. The fix in gRPC-Go 1.79.3 rejects any request whose :path does not begin with / and returns a codes.Unimplemented error; recommended mitigations also include adding request-validation interceptors, normalizing requests upstream, and tightening authorization policies.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A later advisory reported that the same gRPC-Go path canonicalization flaw could enable deny-rule bypass in Traefik deployments using custom middleware or grpc/authz-based authorization. It clarified that canonical policy paths such as /InternalService/SensitiveMethod would not match malformed requests lacking the leading slash.
Version 1.79.3 was released to fix CVE-2026-33186 by rejecting any request whose HTTP/2 :path pseudo-header does not begin with a slash, returning a codes.Unimplemented error. Recommended mitigations also included upgrading, adding validation interceptors, normalizing requests upstream, and tightening authorization policies.
In gRPC-Go versions prior to 1.79.3, malformed HTTP/2 :path values without a leading slash could still be routed while being passed non-canonically to authorization logic. This allowed path-based deny rules in grpc/authz or custom interceptors to be bypassed in affected deployments.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.