CVE-2026-33186
gRPC-Go Authorization Bypass via Malformed Path Header
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
The gRPC-Go library has an authorization bypass vulnerability due to improper validation of the HTTP/2 `:path` pseudo-header. Attackers can exploit this by sending malformed paths to bypass authorization policies on servers with specific deny rules and a fallback allow rule, potentially leading to unauthorized access.