Skip to content

[Aikido] Fix security issue in google.golang.org/grpc via minor version upgrade from 1.79.2 to 1.79.3 in lib#403

Open
aikido-autofix[bot] wants to merge 1 commit intomainfrom
fix/AIK-10927-update-packages-19958098-m4jd
Open

[Aikido] Fix security issue in google.golang.org/grpc via minor version upgrade from 1.79.2 to 1.79.3 in lib#403
aikido-autofix[bot] wants to merge 1 commit intomainfrom
fix/AIK-10927-update-packages-19958098-m4jd

Conversation

@aikido-autofix
Copy link
Contributor

@aikido-autofix aikido-autofix bot commented Mar 19, 2026

Upgrade gRPC-Go to fix authorization bypass vulnerability in HTTP/2 path validation that allows attackers to bypass path-based security policies.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-33186
HIGH
[google.golang.org/grpc] Authorization bypass in HTTP/2 :path pseudo-header validation allows attackers to bypass path-based authorization rules by omitting the leading slash in requests. Affected servers using path-based authorization interceptors with "deny" rules can be exploited to allow unauthorized access.
🔗 Related Tasks

@aikido-autofix aikido-autofix bot changed the title [Aikido] Fix critical issue in google.golang.org/grpc via minor version upgrade from 1.79.2 to 1.79.3 in lib [Aikido] Fix security issue in google.golang.org/grpc via minor version upgrade from 1.79.2 to 1.79.3 in lib Mar 24, 2026
@aikido-autofix aikido-autofix bot force-pushed the fix/AIK-10927-update-packages-19958098-m4jd branch from a6e8867 to 78d72e5 Compare March 24, 2026 00:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants