PT-2026-83123 · Unknown · Grpc-Gateway

·

CVE-2026-37236

·

Published

2026-08-28

·

Updated

2026-09-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions grpc-gateway version 2.28.0
Description Incorrect Access Control occurs because the application processes the X-HTTP-Method-Override header in the ServeMux.ServeHTTP() function without restricting allowed methods. When a POST request with Content-Type set to application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary value provided by the attacker before routing. This behavior enables the bypass of method-based access controls enforced by Web Application Firewalls (WAFs) or upstream proxies.
Recommendations Update grpc-gateway version 2.28.0 to a newer version that contains a fix for this issue. As a temporary mitigation, restrict or filter the X-HTTP-Method-Override header at the proxy or WAF level before it reaches the application.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98253
AZL-98256
AZL-98343
AZL-98346
AZL-98349
AZL-98352
AZL-98355
AZL-98358
AZL-98361
AZL-98364
AZL-98367
AZL-98373
AZL-98376
AZL-98379
AZL-98385
AZL-98388
AZL-98391
AZL-98394
AZL-98436
CVE-2026-37236
OPENSUSE-SU-2026:11667-1
OPENSUSE-SU-2026:11669-1
OPENSUSE-SU-2026:11676-1
OPENSUSE-SU-2026:11697-1
OPENSUSE-SU-2026:11718-1
OPENSUSE-SU-2026:21793-1
OPENSUSE-SU-2026:21801-1
OPENSUSE-SU-2026:21809-1

Affected Products

Grpc-Gateway