Impact
CVE-2026-33186 affects gRPC-Go versions before 1.79.3 [S1]. The upstream advisory describes an authorization-bypass condition in servers that use path-based authorization decisions and allow fallback access when a request path does not match a protected rule [S1]. Advisory severity is critical, but exploitability depends on how a deployed gRPC server handles authorization policy and whether raw HTTP/2 clients can reach it [S1][S2][S3].
Root cause
Affected gRPC-Go releases accepted an HTTP/2 :path pseudo-header that did not start with the canonical leading slash [S1]. The request could still route to the intended handler while authorization logic that inspected the raw method path saw a different, non-canonical value [S1]. Policies that deny the canonical method path but allow unmatched requests can therefore make protected methods reachable in affected deployments [S1].
Affected versions
The affected Go module is google.golang.org/grpc before 1.79.3 [S1][S2][S3]. Version 1.79.3 rejects non-canonical paths before request handling [S1]. Downstream distributions should be checked for a documented backport if the module version itself does not move [S2][S4].
How FixVibe covers it
FixVibe's GitHub repo scans flag Go module or Dep lock metadata that resolves google.golang.org/grpc to a version affected by CVE-2026-33186 / GHSA-p77j-4mvh-x3m3 / GO-2026-4762, with the file, version, fixed version and remediation guidance so you can patch and rebuild the gRPC service.
Fixes and mitigations
Upgrade google.golang.org/grpc to 1.79.3 or newer, regenerate go.sum or Dep metadata, and rebuild every gRPC server binary, worker, sidecar, CI image, container image, or module cache that includes the dependency [S1]. Review path-based authorization policies so malformed, unknown, and non-canonical method paths fail closed before authorization decisions, and keep any reverse proxy or ingress path normalization as defense in depth.
