Skip to content

Security issue in google.golang.org/grpc < v1.79.3 #103

Description

@mnhauke

Summary: VUL-0: CVE-2026-33186: pvetui: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo-header

pvetui currently has an indirect dependy on : google.golang.org/grpc v1.79.1

Security Issue tracked by SUSE (where I maintain the pvetui package)
https://bugzilla.suse.com/show_bug.cgi?id=1260202

Upstream fix of the issue
grpc/grpc-go#8981

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions