THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mwr4-5g34-j5cq (high) — gRPC Erlang package's path bindings are overridable by query string and request body

[GHSA] GHSA-mwr4-5g34-j5cq (high) — gRPC Erlang package's path bindings are overridable by query string and request body

highgithub_advisoriesPublished 2026-08-25

GHSA-mwr4-5g34-j5cq Severity: high CVE: CVE-2026-48599

gRPC Erlang package's path bindings are overridable by query string and request body

### Summary

In the HTTP-to-gRPC transcoding layer of the `grpc` Hex package, query-string and request-body parameters can silently overwrite path-bound fields when building the decoded protobuf request struct. An authenticated attacker who can reach a trans

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mwr4-5g34-j5cq