Skip to content

Fix possible fix(deps): 12 vulnerable dependencies in go.mod - #706

Open
begininvoke wants to merge 1 commit into
uber:mainfrom
begininvoke:redgem/security-fix-2d134736
Open

begininvoke wants to merge 1 commit into
uber:mainfrom
begininvoke:redgem/security-fix-2d134736

Conversation

@begininvoke

Copy link
Copy Markdown

Small change to go.mod — a scan flagged the code below and it looked genuine. It is around line 1.

CRITICAL — Authorization bypass in google.golang.org/grpc (CVE-2026-33186), affecting installed version v1.68.1 in go.mod. The gRPC-Go server's HTTP/2 routing is too lenient: it accepts requests whose :path pseudo-header omits the mandatory leading slash (e.g., Service/Method instead of /Service/Method) and still routes them to the correct handler. However, authorization interceptors — including the official google.golang.org/grpc/authz RBAC interceptor and any custom interceptor that inspects info.FullMethod or grpc.Method(ctx) — evaluate the raw, non-canonical path. As a result, 'deny' rules written against canonical paths (starting with '/') never match these malformed requests, and if the policy contains a fallback 'allow' rule, the request is permitted. Impact: an attacker who can send raw HTTP/2 frames directly to the gRPC server can invoke methods that the path-based authorization policy is supposed to deny, resulting in a complete authorization bypass. Exploitability requires the server to (a) use path-based authz interceptors and (b) have specific deny rules with a default-allow fallback. Risk level: CRITICAL. Remediation: upgrade to v1.79.3, which rejects any :path lacking a leading slash with codes.Unimplemented before it reaches authorization interceptors or handlers. If an immediate upgrade is not possible, apply mitigations such as a validating interceptor that rejects non-canonical paths, infrastructure-level path normalization, or policy hardening (e.g., default-deny fallback).

Updates vulnerable dependencies to recommended versions, covering the reported CVEs.

For reference: rule CVE-2026-33186. Rated critical.

I may well be missing context here — if the current code is deliberate, feel free to close this.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants