Vulnerability Report: GO-2026-4762
- CVE-2026-33186, GHSA-p77j-4mvh-x3m3
- Affects: google.golang.org/grpc
- Published: Mar 27, 2026
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc
For detailed information about this vulnerability, visit https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.79.3
Aliases
References
- https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3
- https://vuln.go.dev/ID/GO-2026-4762.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.