THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qc2q-p7wx-3px3 (medium) — gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

[GHSA] GHSA-qc2q-p7wx-3px3 (medium) — gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

medgithub_advisoriesPublished 2026-09-08

GHSA-qc2q-p7wx-3px3 Severity: medium CVE: CVE-2026-84303

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

### Summary A vulnerability in the xDS RBAC HTTP filter implementation in grpc-go allows remote attackers to bypass authorization policies (specifically DENY rules) by using mixed-case or canonical-case header matchers (e.g., X-Role instead

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qc2q-p7wx-3px3