THREAT OPS › Threat News › [GHSA] GHSA-qc2q-p7wx-3px3 (medium) — gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
[GHSA] GHSA-qc2q-p7wx-3px3 (medium) — gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
GHSA-qc2q-p7wx-3px3 Severity: medium CVE: CVE-2026-84303
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
### Summary A vulnerability in the xDS RBAC HTTP filter implementation in grpc-go allows remote attackers to bypass authorization policies (specifically DENY rules) by using mixed-case or canonical-case header matchers (e.g., X-Role instead
Indicators of compromise
- CVE-2026-84303cve
Original source: https://github.com/advisories/GHSA-qc2q-p7wx-3px3