Skip to content

Update dependencies to address CVE-2026-33186#190

Merged
bestbeforetoday merged 1 commit into
hyperledger:mainfrom
bestbeforetoday:CVE-2026-33186
Mar 23, 2026
Merged

Update dependencies to address CVE-2026-33186#190
bestbeforetoday merged 1 commit into
hyperledger:mainfrom
bestbeforetoday:CVE-2026-33186

Conversation

@bestbeforetoday

Copy link
Copy Markdown
Member

CVE-2026-33186 is a critical vulnerability in gRPC-Go. It is an Authorization Bypass resulting from Improper Input Validation of the HTTP/2 :path pseudo-header. The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed :path headers directly to the gRPC server.

CVE-2026-33186 is a critical vulnerability in gRPC-Go. It is an
Authorization Bypass resulting from Improper Input Validation of the
HTTP/2 :path pseudo-header. The vulnerability is exploitable by an
attacker who can send raw HTTP/2 frames with malformed :path headers
directly to the gRPC server.

Signed-off-by: Mark S. Lewis <Mark.S.Lewis@outlook.com>
@bestbeforetoday bestbeforetoday marked this pull request as ready for review March 23, 2026 13:08
@bestbeforetoday bestbeforetoday requested a review from a team as a code owner March 23, 2026 13:08
@bestbeforetoday bestbeforetoday merged commit 48e8d4a into hyperledger:main Mar 23, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant