← العودة للجدول
CVE-2026-33186
CVE-2026-33186 — A flaw was found in gRPC-Go, the Go language implementation of gRPC. This vulner
📅 2026-06-08
🔴 Critical 🔥 No CIRCL CVE Exploit Exploit CVSS 9.1

📋 الوصف الكامل

A flaw was found in gRPC-Go, the Go language implementation of gRPC. This vulnerability, an authorization bypass, is caused by improper input validation of the HTTP/2 `:path` pseudo-header. A remote attacker can exploit this by sending raw HTTP/2 frames with a malformed `:path` that omits the mandatory leading slash. This allows the attacker to bypass defined security policies, potentially leading

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-33186

📡 المصدر

CIRCL CVE

✅ الحلول والتخفيف

Refer to CVE-2026-33186 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←