CVE-2026-37236
Aliases:DEBIAN-CVE-2026-37236UBUNTU-CVE-2026-37236openSUSE-SU-2026:11669-1
Advisory lineage Upstream: 0 Downstream: 13
Deferred
Published: 28 Aug 2026, 00:00
Last modified:02 Sept 2026, 18:14
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
0.44% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
28 Aug 2026, 00:00
Published
Vulnerability first disclosed
02 Sept 2026, 18:14
Last Modified
Vulnerability information updated
Description
grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.44%• Percentile: 38%
Techniques & Countermeasures
- CWE-639•Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Affected Systems
- debian•golang-github-grpc-ecosystem-grpc-gateway
all | all | all | all | < 2.30.0-1
- ubuntu•golang-github-grpc-ecosystem-grpc-gateway
all | all | all | all | all
- opensuse•helm3&distro=openSUSE Tumbleweed
< 3.21.3-7.1
References (7)
- https://github.com/grpc-ecosystem/grpc-gateway/commit/72123cd4f32545f6e1376873f412dcdcbcf29acc
- https://github.com/grpc-ecosystem/grpc-gateway
- https://s00me00ne.com/cve/cve-2026-37236/
- https://security-tracker.debian.org/tracker/CVE-2026-37236
- https://ubuntu.com/security/CVE-2026-37236
- https://www.cve.org/CVERecord?id=CVE-2026-37236
- https://www.suse.com/security/cve/CVE-2026-37236