FixVibe

critical

Authorization Bypass in gRPC-Go via HTTP/2 :path Pseudo-Header (CVE-2026-33186)

CVE-2026-33186 affects gRPC-Go servers that combine affected versions with path-based authorization and fallback-allow policy behavior. FixVibe GitHub repo scans flag google.golang.org/grpc versions before 1.79.3.

CVE-2026-33186GHSA-p77j-4mvh-x3m3GO-2026-4762CWE-285CWE-20

Impact

CVE-2026-33186 affects gRPC-Go versions before 1.79.3 [S1]. The upstream advisory describes an authorization-bypass condition in servers that use path-based authorization decisions and allow fallback access when a request path does not match a protected rule [S1]. Advisory severity is critical, but exploitability depends on how a deployed gRPC server handles authorization policy and whether raw HTTP/2 clients can reach it [S1][S2][S3].

Root cause

Affected gRPC-Go releases accepted an HTTP/2 :path pseudo-header that did not start with the canonical leading slash [S1]. The request could still route to the intended handler while authorization logic that inspected the raw method path saw a different, non-canonical value [S1]. Policies that deny the canonical method path but allow unmatched requests can therefore make protected methods reachable in affected deployments [S1].

Affected versions

The affected Go module is google.golang.org/grpc before 1.79.3 [S1][S2][S3]. Version 1.79.3 rejects non-canonical paths before request handling [S1]. Downstream distributions should be checked for a documented backport if the module version itself does not move [S2][S4].

How FixVibe covers it

FixVibe's GitHub repo scans flag Go module or Dep lock metadata that resolves google.golang.org/grpc to a version affected by CVE-2026-33186 / GHSA-p77j-4mvh-x3m3 / GO-2026-4762, with the file, version, fixed version and remediation guidance so you can patch and rebuild the gRPC service.

Fixes and mitigations

Upgrade google.golang.org/grpc to 1.79.3 or newer, regenerate go.sum or Dep metadata, and rebuild every gRPC server binary, worker, sidecar, CI image, container image, or module cache that includes the dependency [S1]. Review path-based authorization policies so malformed, unknown, and non-canonical method paths fail closed before authorization decisions, and keep any reverse proxy or ingress path normalization as defense in depth.