VDB
RHSA-2026%3A17459
RHSA-2026%3A17459
PUBLISHED
CVSS 9.100000381469727 CRITICAL
A flaw was found in gRPC-Go, the Go language implementation of gRPC. This vulnerability, an authorization bypass, is caused by improper input validation of the HTTP/2 `:path` pseudo-header. A remote attacker can exploit this by sending raw HTTP/2 frames with a malformed `:path` that omits the mandatory leading slash. This allows the attacker to bypass defined security policies, potentially leading to unauthorized access to services or information disclosure.
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-rhel8@sha256:da3da57c5810ac09246d6e26c7eb1e0e82237f5cdcfa19a5dada1382e1938986_s390x as a component of multicluster engine for Kubernetes 2.6 | |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-image-service-rhel8@sha256:09ba33e68d741089a8e607c20ae1af90ef0f91886dbbfe5631a8b75bb4669db7_ppc64le as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel8@sha256:1f7f0ecf658912226a17b7f08f9c1e1d0f3ebc3b8418e22a1fc4f2c62acd0af0_amd64 as a component of multicluster engine for Kubernetes 2.6 | |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-rhel8@sha256:da3da57c5810ac09246d6e26c7eb1e0e82237f5cdcfa19a5dada1382e1938986_s390x as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | multicluster-engine/assisted-installer-agent-rhel8 | |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-rhel8@sha256:28007e6ad17db1c94a61585ccee27e988faf87fc0e24330e7d298609687090f3_arm64 as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-image-service-rhel8@sha256:a805ad07ffbc1fd7de08b256b13fcb9cb8683f3ec13673905e62b4243072ce21_arm64 as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:db4f87f2ad1583f656147c4cf1a80becc7947c785022a131843ce60bb05f2f28_amd64 as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | multicluster engine for Kubernetes | |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-image-service-rhel8@sha256:c667241161d798e4cbd92213630cffa4753c7234b723f4cd41838c9f7bae99e9_amd64 as a component of multicluster engine for Kubernetes 2.6 | |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel8@sha256:4f149b015e37d57ebbb3c50b40dff8c836293a63c0fcf410a8481f50c675d7de_s390x as a component of multicluster engine for Kubernetes 2.6 | |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-rhel8@sha256:689e63be09baa0e043df979b866d0127f2c8c1e8615725044f3185ed104f6c52_ppc64le as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-image-service-rhel8@sha256:c667241161d798e4cbd92213630cffa4753c7234b723f4cd41838c9f7bae99e9_amd64 as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel8@sha256:2282ac22b99efbbe20be15ee09bbbdf22fd6ea8c9a996d33e21ccdc10fdc1458_arm64 | |
| Red Hat | Multicluster Engine for Kubernetes 2.6 | |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel8@sha256:1b4075ffcd5abcc5b7b08d712f68d8dd5a679553e9abcfe01fb762a2eaa90286_amd64 as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel8@sha256:1f7f0ecf658912226a17b7f08f9c1e1d0f3ebc3b8418e22a1fc4f2c62acd0af0_amd64 as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel8@sha256:c4eaf8442a49e5ee5cd6e22e9bde7452f8bf7d40ae3faeb5e26019032bb24876_ppc64le as a component of multicluster engine for Kubernetes 2.6 | |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:2943c61fe779e15791fd0c806628b3e288735ceb18420ae68d4193e404c04a95_ppc64le as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel8@sha256:2282ac22b99efbbe20be15ee09bbbdf22fd6ea8c9a996d33e21ccdc10fdc1458_arm64 as a component of multicluster engine for Kubernetes 2.6 | *, *, * |
…and 16 more
Timeline
- May 14, 2026 CVE Published
- May 15, 2026 Distribution Patch
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- Jul 22, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:17459 advisory
- https://access.redhat.com/security/cve/CVE-2026-33186 advisory
- https://access.redhat.com/security/cve/CVE-2026-34986 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17459.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2449833 issue
- https://www.cve.org/CVERecord?id=CVE-2026-33186 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-33186 advisory
- https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2455470 issue
- https://www.cve.org/CVERecord?id=CVE-2026-34986 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34986 advisory
- https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8 advisory
- https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants advisory