Skip to content

CVE-2028-33186: google.golang.org/grpc v1.79.1 authorization bypass #2577

@scobbe

Description

@scobbe

Summary

Cloud SQL Proxy v2.21.2 bundles google.golang.org/grpc v1.79.1, which is affected by CVE-2028-33186 (Critical): an authorization bypass via missing leading slash in :path. The fix is available in grpc v1.79.3.

Impact

gRPC-Go has an authorization bypass via missing leading slash in :path. The worst case impact is "Attacker can abuse improper authorization."

Requested Fix

Bump google.golang.org/grpc from v1.79.1 to v1.79.3 (or later) in the next release.

References

  • CVE-2028-33186
  • Detected via Aikido security scanner on the gcr.io/cloud-sql-connectors/cloud-sql-proxy:2.21.2 container image

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions