CRITICAL
grpc-ecosystem
CVE published 2026-08-28
CVE-2026-37236
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T16:17:46.157Z and has not been modified since then. grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control due to improper handling of the X-HTTP-Method-Override header. This allows attackers to bypass method-based access controls enforced by upstream proxies or WAFs. The vulnerability im [truncated]