THREAT OPS › Threat News › [GHSA] GHSA-mwr4-5g34-j5cq (high) — gRPC Erlang package's path bindings are overridable by query string and request body
[GHSA] GHSA-mwr4-5g34-j5cq (high) — gRPC Erlang package's path bindings are overridable by query string and request body
GHSA-mwr4-5g34-j5cq Severity: high CVE: CVE-2026-48599
gRPC Erlang package's path bindings are overridable by query string and request body
### Summary
In the HTTP-to-gRPC transcoding layer of the `grpc` Hex package, query-string and request-body parameters can silently overwrite path-bound fields when building the decoded protobuf request struct. An authenticated attacker who can reach a trans
Indicators of compromise
- 8aaf3d3a8c4c7b08ac65e9c6f254e0d24da1d048sha1
- 33b6a095dbc91c6dee3c7b90893d7d74952e82e4sha1
- CVE-2026-48599cve
Original source: https://github.com/advisories/GHSA-mwr4-5g34-j5cq