---
id: GO-2026-6061
aliases:
  - GHSA-hrxh-6v49-42gf
title: >-
  Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport
  server implementation in google.golang.org/grpc
summary: >-
  Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport
  server implementation in google.golang.org/grpc
severity: none
vendor: grpc
product: google.golang.org/grpc
ecosystem: go
affected:
  - google.golang.org/grpc < 1.82.1
patched:
  - google.golang.org/grpc 1.82.1
published: '2026-07-27'
updated: '2026-07-27'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-6061'
references:
  - url: 'https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf'
  - url: >-
      https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935
  - url: 'https://github.com/grpc/grpc-go/pull/9236'
  - url: 'https://github.com/grpc/grpc-go/releases/tag/v1.82.1'
tags:
  - osv
  - go
ingestedAt: '2026-07-27T19:08:56.063Z'
---

## Overview

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

## Affected packages

- `google.golang.org/grpc < 1.82.1`

## Remediation

Upgrade to a patched release:

- `google.golang.org/grpc 1.82.1`
