CVE-2026-37236

NameCVE-2026-37236
Descriptiongrpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-github-grpc-ecosystem-grpc-gateway (PTS)bullseye (security)1.6.4-2+deb11u1vulnerable
bookworm, bullseye1.6.4-2vulnerable
trixie2.20.0-2vulnerable
forky2.27.2-3vulnerable
sid2.30.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-github-grpc-ecosystem-grpc-gatewaysource(unstable)2.30.0-1

Notes

https://github.com/grpc-ecosystem/grpc-gateway/commit/72123cd4f32545f6e1376873f412dcdcbcf29acc (v2.29.0)

Search for package or bug name: Reporting problems