gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific "deny" rules for canonical paths but allows other requests by default (a fallback "allow" rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers with a non-canonical path string. While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods: Use a validating interceptor (recommended mitigation); infrastructure-level normalization; and/or policy hardening.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade osbuild-composer-coreUpgrade opentelemetry-collectorUpgrade osbuild-composerUpgrade osbuild-composer-worker | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade grpcUpgrade rclone | Jun 18, 2026 | Mar 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade runfinch-finchUpgrade amazon-cloudwatch-agentUpgrade ecs-initUpgrade nerdctlUpgrade containerd-stressUpgrade containerd-debuginfoUpgrade dockerUpgrade rclone-debuginfoUpgrade nerdctl-debuginfoUpgrade soci-snapshotterUpgrade cri-toolsUpgrade rcloneUpgrade docker-debuginfoUpgrade containerdUpgrade cri-tools-debuginfo | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade amazon-cloudwatch-agentUpgrade ecs-initUpgrade nerdctlUpgrade containerd-stressUpgrade runfinch-finchUpgrade containerd-stress-debuginfoUpgrade rclone-debugsourceUpgrade soci-snapshotterUpgrade credentials-fetcherUpgrade rclone-debuginfoUpgrade rcloneUpgrade containerd-debuginfoUpgrade containerdUpgrade containerd-debugsource | Apr 14, 2026 | Mar 20, 2026 |
| Freebsd | — | Upgrade traefik | Mar 30, 2026 | Mar 29, 2026 |
| Redhat Openshift | — | Upgrade microshiftUpgrade ose-azure-acr-image-credential-provider | Aug 10, 2026 | Mar 20, 2026 |
| Redhat_linux | — | No solution existsUpgrade kernel-rtUpgrade kernel | Apr 28, 2026 | Mar 20, 2026 |
| Rocky_linux | — | Upgrade osbuild-composer-debuginfoUpgrade image-builder-debugsourceUpgrade osbuild-composer-core-debuginfoUpgrade osbuild-composer-coreUpgrade image-builderUpgrade osbuild-composer-debugsourceUpgrade image-builder-debuginfoUpgrade osbuild-composer-workerUpgrade osbuild-composerUpgrade osbuild-composer-worker-debuginfoUpgrade opentelemetry-collector | Jun 1, 2026 | May 28, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 10.2.6Upgrade Splunk Enterprise to version 9.4.14Upgrade Splunk Enterprise to version 10.4.2Upgrade Splunk Enterprise to version 10.0.9 | Aug 20, 2026 | Mar 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub