Skip to content

CVE-2026-33186 google.golang.org/grpc false-positive #11283

@bmwiedemann

Description

@bmwiedemann

Checklist

Installation method

built from source

Version

master

Config

Description

https://bugzilla.suse.com/show_bug.cgi?id=1260233 notified me of CVE-2026-33186:

kubo: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo-header

That affects the version 1.79.2 used in kubo atm. Please update to version 1.79.3 or later.

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/maintenanceWork required to avoid breaking changes or harm to project's status quoneed/triageNeeds initial labeling and prioritization

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions