AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-37236.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.3No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSMicrosoft vendor recordModified Oct 07, 2026

Disclosure summary

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

Microsoft Security Updates (CVRF) · 2026-Aug

Open original source · Updated Oct 07, 2026

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.

Microsoft maximum product score: 5.3

VendorProduct / associationVersion / bounds
Microsoft update guideazl3 cert-manager 1.12.15-11 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 cf-cli 8.7.11-8 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 cloud-provider-kubevirt 0.5.1-6 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 docker-buildx 0.14.0-16 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 docker-compose 2.27.0-13 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 etcd 3.5.33-1 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 flannel 0.24.2-29 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 keda 2.14.1-16 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 kube-vip-cloud-provider 0.0.10-7 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 moby-containerd-cc 1.7.7-16 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 telegraf 1.31.0-28 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 containerd2 2.2.4-8 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 keda 2.14.1-18 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 kube-vip-cloud-provider 0.0.10-8 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 moby-engine 25.0.3-20 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 prometheus-adapter 0.12.0-9 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 cf-cli 8.7.11-9 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 flannel 0.24.2-32 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 moby-containerd-cc 1.7.7-17 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 containerd2 2.2.4-6 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 cri-tools 1.32.0-7 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 kubernetes 1.30.10-27 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 moby-engine 25.0.3-19 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 prometheus-adapter 0.12.0-7 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 cert-manager 1.12.15-12 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 cloud-provider-kubevirt 0.5.1-7 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 flannel 0.24.2-31 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 kubernetes 1.30.10-29 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 telegraf 1.31.0-31 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 containerd2 2.3.4-1 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 cri-tools 1.32.0-8 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 docker-buildx 0.14.0-17 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 docker-compose 2.27.0-14 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 keda 2.14.1-19 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 kubernetes 1.30.10-30 on Azure Linux 3.0 (MSRC status code 3)
Microsoft update guideazl3 prometheus-adapter 0.12.0-10 on Azure Linux 3.0 (MSRC status code 3)

Vendor remediation references

  • Vendor guidance · product IDs 21688-17084, 21744-17084, 21745-17084, 21741-17084, 21746-17084, 21693-17084, 21769-17084, 21652-17084, 21691-17084, 21747-17084
  • Vendor guidance · product IDs 21688-17084, 21744-17084, 21745-17084, 21741-17084, 21746-17084, 21693-17084, 21769-17084, 21652-17084, 21691-17084, 21747-17084
  • Vendor guidance · build 8.7.11-9 · product IDs 21768-17084
  • Vendor guidance · product IDs 21768-17084
  • Vendor guidance · build 0.14.0-17 · product IDs 21743-17084
  • Vendor guidance · product IDs 21743-17084
  • Vendor guidance · build 2.27.0-14 · product IDs 21682-17084
  • Vendor guidance · product IDs 21682-17084
  • Release Notes · product IDs 21771-17084
  • Vendor guidance · product IDs 21771-17084
  • Vendor guidance · build 1.7.7-17 · product IDs 21705-17084
  • Vendor guidance · product IDs 21705-17084
  • Vendor guidance · build 2.2.4-9 · product IDs 21828-17084
  • Vendor guidance · product IDs 21828-17084
  • Vendor guidance · build 2.14.1-19 · product IDs 21831-17084, 21904-17084
  • Vendor guidance · product IDs 21831-17084, 21904-17084
  • Vendor guidance · build 0.0.10-10 · product IDs 21833-17084
  • Vendor guidance · product IDs 21833-17084
  • Release Notes · build 25.0.3-21 · product IDs 21807-17084
  • Vendor guidance · product IDs 21807-17084
  • Vendor guidance · build 0.12.0-10 · product IDs 21834-17084
  • Vendor guidance · product IDs 21834-17084
  • Release Notes · build 8.7.11-9 · product IDs 21907-17084
  • Vendor guidance · product IDs 21907-17084
  • Release Notes · build 0.24.2-32 · product IDs 21912-17084
  • Vendor guidance · product IDs 21912-17084
  • Release Notes · build 1.7.7-17 · product IDs 21913-17084
  • Vendor guidance · product IDs 21913-17084
  • Vendor guidance · build 1.32.0-8 · product IDs 21770-17084
  • Vendor guidance · product IDs 21770-17084
  • Vendor guidance · build 1.12.15-14 · product IDs 21826-17084
  • Vendor guidance · product IDs 21826-17084
  • Vendor guidance · build 0.5.1-9 · product IDs 21827-17084
  • Vendor guidance · product IDs 21827-17084
  • Vendor guidance · build 0.24.2-32 · product IDs 21830-17084
  • Vendor guidance · product IDs 21830-17084
  • Vendor guidance · build 1.30.10-30 · product IDs 21832-17084
  • Vendor guidance · product IDs 21832-17084
  • Vendor guidance · build 1.31.0-33 · product IDs 21836-17084
  • Vendor guidance · product IDs 21836-17084
  • Release Notes · build 2.3.4-1 · product IDs 21908-17084
  • Vendor guidance · product IDs 21908-17084
  • Release Notes · build 1.32.0-8 · product IDs 21909-17084
  • Vendor guidance · product IDs 21909-17084
  • Release Notes · build 0.14.0-17 · product IDs 21910-17084
  • Vendor guidance · product IDs 21910-17084
  • Release Notes · build 2.27.0-14 · product IDs 21911-17084
  • Vendor guidance · product IDs 21911-17084
  • Release Notes · build 1.30.10-30 · product IDs 21893-17084
  • Vendor guidance · product IDs 21893-17084
  • Release Notes · build 0.12.0-10 · product IDs 21914-17084
  • Vendor guidance · product IDs 21914-17084

Original records & references

PUBLISHED 2026-09-01T21:04:47-04:00
MODIFIED 2026-10-07T10:45:25-04:00
INGESTED 2026-10-08T12:35:09-04:00