VYPR

grpc-gateway

by Grpc Ecosystem

CVEs (1)

  • CVE-2026-37236Aug 28, 2026
    risk 0.00cvss epss

    grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header,…