VDB

RHSA-2026%3A23234

RHSA-2026%3A23234 PUBLISHED CVSS 9.100000381469727 CRITICAL

A flaw was found in gRPC-Go, the Go language implementation of gRPC. This vulnerability, an authorization bypass, is caused by improper input validation of the HTTP/2 `:path` pseudo-header. A remote attacker can exploit this by sending raw HTTP/2 frames with a malformed `:path` that omits the mandatory leading slash. This allows the attacker to bypass defined security policies, potentially leading to unauthorized access to services or information disclosure.

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/openshift4/ose-cluster-openshift-apiserver-rhel9-operator@sha256:6813b2ce99c28baccd860c250f02bad3a47983cae7d5110451a6cca2a2105c59_s390x as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator@sha256:ae238e86bc297b800b49ca831343d8543b51804f3b63eeeb838a0a8d5664b310_ppc64le as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-powervs-block-csi-driver-operator-rhel8@sha256:d5400ffe7a80037c36053ffa01fc9ece0eddc4c31e4dff92bdb39a1a37031645_amd64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-machine-os-images-rhel8@sha256:ab79462d39932f05b35f53c7296837a2215f8a967942a011cb3611f3964dafa8_amd64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-machine-os-images-rhel8@sha256:6a5b0d976324356142d0354670e5bdd41f3895d1db7496749f2d9df50fcea17d_s390x as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-csi-external-provisioner-rhel8@sha256:a7065a54a7e65482c131f47513c26a669469e3d3eb6d69dc7ec010c9fd83feb5_arm64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-cluster-kube-apiserver-rhel9-operator@sha256:736fafe4dcbd457a162d336951f74cbb72242f778b48ca8e66b057468a9fc265_arm64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-csi-driver-nfs-rhel9@sha256:a6110be4dccce4f9bd7a677edb72ff3ee3ece4388ba32a32864c9898fa18fccd_amd64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-must-gather@sha256:1425f3f0dd181107d333a18e639f5744abe04ce63e7c7073c2378d6f44116d3a_amd64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-cluster-kube-cluster-api-rhel9-operator@sha256:b75e2765e743eae613187cc455f341c4d4e2d54493f0775d320fa94d5ededc75_s390x as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-service-ca-rhel9-operator@sha256:08c4acc93316a27f5420d23418903decf357952bc358a02e8c14d2bd20453e46_ppc64le as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator@sha256:67942e19617d07675a44b1fc13261c193a80f35582ca3484092dcfab7b8cbd64_ppc64le as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-cluster-kube-scheduler-rhel9-operator@sha256:a5c04ca4fe5b341fa0c432b5d8ffe3e6ed4591d71d406974d0ebcefe1c92cfe5_amd64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-csi-node-driver-registrar-rhel8@sha256:6f399948c7c03ccdef1b97aae7687287eb569d5a1978de1759b40c33a443f574_arm64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-machine-api-rhel9-operator@sha256:c0b7aa5c302d8bea17db2e4e761db552dbc9315389ef1641cb068b6f4cf98fc9_s390x as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-openstack-cloud-controller-manager-rhel9@sha256:54da109bda292c8205a153d7050ce3f2319957da4f6ee447d7c4716045730710_ppc64le as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-agent-installer-utils-rhel9@sha256:979949d343b9f169c1196cc43c34d2807132c4c9ef949fae533e0ffaefbecdfb_amd64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-cluster-storage-rhel9-operator@sha256:7fb58aaadd191aed1fb965bfaf5ee5b5f78a129dc518f60eb6499c485dc4aa18_ppc64le as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/ose-coredns-rhel9@sha256:d03de612e617eccacc38917749c7c65d98513a574af22c50aa02cef6453db2e2_s390x as a component of Red Hat OpenShift Container Platform 4.15*, *, *
Red Hatregistry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:a8ff637b55e2df5564a442d1a40b4031e93eb9c0ffd5aa014e411cd0783dc3c4_arm64 as a component of Red Hat OpenShift Container Platform 4.15*, *, *

…and 644 more

Timeline

  • Jun 11, 2026 CVE Published
  • Jun 11, 2026 Distribution Patch
  • Jun 11, 2026 Distribution Patch
  • Jun 11, 2026 Security Advisory
  • Jun 11, 2026 Security Advisory
  • Jun 11, 2026 Security Advisory
  • Jul 20, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›