Skip to content
Shivasurya
writing
projects
talks
research
books
about
Authorization-Bypass
CVE-2026-33186: Bypassing gRPC-Go Authorization with a Missing Slash
Apr 1, 2026
CVE-2026-33186 - A path normalization flaw in grpc-go v1.79.2 and earlier allows attackers to bypass path-based authorization interceptors by omitting the leading slash.