{"id":"GO-2026-6061","aliases":["GHSA-hrxh-6v49-42gf"],"title":"Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc","summary":"Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc","severity":"none","vendor":"grpc","product":"google.golang.org/grpc","ecosystem":"go","affected":["google.golang.org/grpc < 1.82.1"],"patched":["google.golang.org/grpc 1.82.1"],"published":"2026-07-27","updated":"2026-07-27","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GO-2026-6061","references":[{"url":"https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf"},{"url":"https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935"},{"url":"https://github.com/grpc/grpc-go/pull/9236"},{"url":"https://github.com/grpc/grpc-go/releases/tag/v1.82.1"}],"tags":["osv","go"],"ingestedAt":"2026-07-27T19:08:56.063Z","slug":"GO-2026-6061","body":"## Overview\n\nVulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc\n\n## Affected packages\n\n- `google.golang.org/grpc < 1.82.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `google.golang.org/grpc 1.82.1`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}