Vulnerability GO-2026-6441

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 hours ago
September 15, 2026 at 06:39 PM UTC
Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc
v1.0.0 - v1.83.0
v1.0.0 - v1.83.0

Summary

Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc

Details

In google.golang.org/grpc, the xDS RBAC HTTP filter does not lowercase header matcher names before evaluating them against incoming request metadata. When an RBAC policy defines rules (such as DENY) referencing headers with uppercase or mixed-case characters, the rule fails to match, causing authorization policies to fail open. Additionally, callers can evade gRFC A41 validation blocking "grpc-" prefixed headers and ":scheme" via variations in casing.

Impacted packages

Timeline

Published
4 hours ago
September 15, 2026 at 06:39 PM UTC
Last Modified
4 hours ago
September 15, 2026 at 07:00 PM UTC