Red Hat Security Advisory: osbuild-composer security update
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
gRPC-Go versions before 1.79.3 improperly validate the HTTP/2 :path pseudo-header by accepting paths without the mandatory leading slash (e.g., 'Service/Method' instead of '/Service/Method'). While the server routes these requests correctly, authorization interceptors evaluate the raw, non-canonical path, causing deny rules defined with canonical paths to fail to match. This leads to an authorization bypass if fallback allow rules exist. The vulnerability affects grpc-go servers that use path-based authorization interceptors such as the official RBAC implementation in google.golang.org/grpc/authz or custom interceptors relying on info.FullMethod or grpc.Method(ctx). A remote attacker can exploit this by sending malformed HTTP/2 frames with a :path missing the leading slash, potentially gaining unauthorized access or causing information disclosure. Red Hat has acknowledged this issue affecting OpenShift Container Platform and advises upgrading to fixed package versions. Mitigation can also be achieved by normalizing the :path header at the proxy or API gateway level before requests reach the grpc-go server.
Potential Impact
The vulnerability allows remote attackers to bypass authorization policies on grpc-go servers that rely on path-based authorization interceptors. This can lead to unauthorized access to services or information disclosure. The CVSS v3.1 base score is 9.1 (critical), reflecting high confidentiality and integrity impact with no required privileges or user interaction. There are no known exploits in the wild as of the latest information. Red Hat rates the impact as low for their OpenShift Container Platform packages but acknowledges the underlying criticality of the flaw.
Mitigation Recommendations
A fix is available in grpc-go version 1.79.3 and later. Users should upgrade to this or later versions to remediate the vulnerability. For environments where immediate upgrade is not possible, implement infrastructure-level normalization of the HTTP/2 :path pseudo-header to ensure it includes the mandatory leading slash before reaching the grpc-go server. This can be done by configuring a reverse proxy or API gateway to validate and normalize incoming requests. Ensure any such intermediary is properly configured and restarted to apply changes. Red Hat OpenShift Container Platform users should upgrade to the 4.13.67 release or later when available. No other vendor-provided fixes or mitigations are noted. Patch status is confirmed by Red Hat advisories.
Red Hat Security Advisory: osbuild-composer security update
Description
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
gRPC-Go versions before 1.79.3 improperly validate the HTTP/2 :path pseudo-header by accepting paths without the mandatory leading slash (e.g., 'Service/Method' instead of '/Service/Method'). While the server routes these requests correctly, authorization interceptors evaluate the raw, non-canonical path, causing deny rules defined with canonical paths to fail to match. This leads to an authorization bypass if fallback allow rules exist. The vulnerability affects grpc-go servers that use path-based authorization interceptors such as the official RBAC implementation in google.golang.org/grpc/authz or custom interceptors relying on info.FullMethod or grpc.Method(ctx). A remote attacker can exploit this by sending malformed HTTP/2 frames with a :path missing the leading slash, potentially gaining unauthorized access or causing information disclosure. Red Hat has acknowledged this issue affecting OpenShift Container Platform and advises upgrading to fixed package versions. Mitigation can also be achieved by normalizing the :path header at the proxy or API gateway level before requests reach the grpc-go server.
Potential Impact
The vulnerability allows remote attackers to bypass authorization policies on grpc-go servers that rely on path-based authorization interceptors. This can lead to unauthorized access to services or information disclosure. The CVSS v3.1 base score is 9.1 (critical), reflecting high confidentiality and integrity impact with no required privileges or user interaction. There are no known exploits in the wild as of the latest information. Red Hat rates the impact as low for their OpenShift Container Platform packages but acknowledges the underlying criticality of the flaw.
Mitigation Recommendations
A fix is available in grpc-go version 1.79.3 and later. Users should upgrade to this or later versions to remediate the vulnerability. For environments where immediate upgrade is not possible, implement infrastructure-level normalization of the HTTP/2 :path pseudo-header to ensure it includes the mandatory leading slash before reaching the grpc-go server. This can be done by configuring a reverse proxy or API gateway to validate and normalize incoming requests. Ensure any such intermediary is properly configured and restarted to apply changes. Red Hat OpenShift Container Platform users should upgrade to the 4.13.67 release or later when available. No other vendor-provided fixes or mitigations are noted. Patch status is confirmed by Red Hat advisories.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:11330
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-33211","CVE-2026-33810"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a160956e29bf47b5061b109
Added to database: 05/26/2026, 20:57:58 UTC
Last enriched: 08/17/2026, 18:48:37 UTC
Last updated: 09/15/2026, 06:26:05 UTC
Views: 113
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.