{"id":"GHSA-46wh-3698-f2cx","aliases":["GO-2026-4897"],"url":"https://o3.security/vulnerability/GHSA-46wh-3698-f2cx","summary":"Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)","details":"## Summary\n\nThere is a potential vulnerability in Traefik due to its dependency on an affected version of gRPC-Go (CVE-2026-33186).\n\nA remote, unauthenticated attacker can send gRPC requests with a malformed HTTP/2 `:path` pseudo-header omitting the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server routes such requests correctly, path-based authorization interceptors evaluate the raw non-canonical path and fail to match \"deny\" rules, allowing the request to bypass the policy entirely if a fallback \"allow\" rule is present.\n\n## Patches\n\n- https://github.com/traefik/traefik/releases/tag/v2.11.42\n- https://github.com/traefik/traefik/releases/tag/v3.6.12\n- https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3\n\n## For more information\n\nIf there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).\n\n<details>\n<summary>Original Description</summary>\n\n### Summary\nThis CVE hits traefik until Version 3.6.11 and 2.11.41.\ngRPC-Go has an authorization bypass via missing leading slash in :path\n### Details\nAs described in https://github.com/advisories/GHSA-p77j-4mvh-x3m3\n### PoC\nUpdate library version in \nhttps://github.com/traefik/traefik/blob/67c64ed9b25fbb90f1086977a62827133a7aa01b/go.mod#L108\n### Impact\nIs described in https://github.com/advisories/GHSA-p77j-4mvh-x3m3\n\n</details>\n\n\n----------","published":"2026-03-29T15:37:28Z","modified":"2026-09-10T03:50:36.980577799Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/traefik/traefik/v2","fixedVersion":"2.11.42"},{"ecosystem":"Go","name":"github.com/traefik/traefik/v3","fixedVersion":"3.6.12"},{"ecosystem":"Go","name":"github.com/traefik/traefik/v3","fixedVersion":"3.7.0-ea.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/traefik/traefik/security/advisories/GHSA-46wh-3698-f2cx"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-p77j-4mvh-x3m3"},{"type":"PACKAGE","url":"https://github.com/traefik/traefik"},{"type":"WEB","url":"https://github.com/traefik/traefik/blob/67c64ed9b25fbb90f1086977a62827133a7aa01b/go.mod#L108"},{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v2.11.42"},{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v3.6.12"},{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:36.980577799Z"}}