Skip to content

gh bundles google.golang.org/grpc affected by CVE-2026-33186 (authorization bypass) #13275

@Frostburn2332

Description

@Frostburn2332

gh currently bundles google.golang.org/grpc at a version affected by CVE-2026-33186 — an authorization bypass caused by a missing leading slash in :path.

The server-side bypass doesn't apply to gh itself (it's a client, not a gRPC server), so this is not directly exploitable in gh's use case. However, image scanners flag gh binaries for this CVE, forcing downstream consumers to suppress it.

The fix is in grpc-go v1.79.3. Could a gh release be cut that picks up grpc-go >= 1.79.3?

Filed to track on our side — happy to share more context if helpful.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions