{"id":"GHSA-46wh-3698-f2cx","aliases":["GO-2026-4897"],"title":"Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)","summary":"Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)","severity":"high","vendor":"traefik","product":"github.com/traefik/traefik/v2","ecosystem":"go","affected":["github.com/traefik/traefik/v2 < 2.11.42","github.com/traefik/traefik/v3 >= 3.0.0-beta3, < 3.6.12","github.com/traefik/traefik/v3 >= 3.7.0-ea.1, < 3.7.0-ea.3"],"patched":["github.com/traefik/traefik/v2 2.11.42","github.com/traefik/traefik/v3 3.6.12","github.com/traefik/traefik/v3 3.7.0-ea.3"],"published":"2026-03-29","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:36.980577799Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-46wh-3698-f2cx","references":[{"url":"https://github.com/traefik/traefik/security/advisories/GHSA-46wh-3698-f2cx"},{"url":"https://github.com/advisories/GHSA-p77j-4mvh-x3m3"},{"url":"https://github.com/traefik/traefik"},{"url":"https://github.com/traefik/traefik/blob/67c64ed9b25fbb90f1086977a62827133a7aa01b/go.mod#L108"},{"url":"https://github.com/traefik/traefik/releases/tag/v2.11.42"},{"url":"https://github.com/traefik/traefik/releases/tag/v3.6.12"},{"url":"https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3"}],"tags":["osv","go"],"ingestedAt":"2026-09-12T03:13:01.751Z","slug":"GHSA-46wh-3698-f2cx","body":"## Overview\n\n## Summary\n\nThere is a potential vulnerability in Traefik due to its dependency on an affected version of gRPC-Go (CVE-2026-33186).\n\nA remote, unauthenticated attacker can send gRPC requests with a malformed HTTP/2 `:path` pseudo-header omitting the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server routes such requests correctly, path-based authorization interceptors evaluate the raw non-canonical path and fail to match \"deny\" rules, allowing the request to bypass the policy entirely if a fallback \"allow\" rule is present.\n\n## Patches\n\n- https://github.com/traefik/traefik/releases/tag/v2.11.42\n- https://github.com/traefik/traefik/releases/tag/v3.6.12\n- https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3\n\n## For more information\n\nIf there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).\n\n<details>\n<summary>Original Description</summary>\n\n### Summary\nThis CVE hits traefik until Version 3.6.11 and 2.11.41.\ngRPC-Go has an authorization bypass via missing leading slash in :path\n### Details\nAs described in https://github.com/advisories/GHSA-p77j-4mvh-x3m3\n### PoC\nUpdate library version in \nhttps://github.com/traefik/traefik/blob/67c64ed9b25fbb90f1086977a62827133a7aa01b/go.mod#L108\n### Impact\nIs described in https://github.com/advisories/GHSA-p77j-4mvh-x3m3\n\n</details>\n\n\n----------\n\n## Affected packages\n\n- `github.com/traefik/traefik/v2 < 2.11.42`\n- `github.com/traefik/traefik/v3 >= 3.0.0-beta3, < 3.6.12`\n- `github.com/traefik/traefik/v3 >= 3.7.0-ea.1, < 3.7.0-ea.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/traefik/traefik/v2 2.11.42`\n- `github.com/traefik/traefik/v3 3.6.12`\n- `github.com/traefik/traefik/v3 3.7.0-ea.3`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}