Junglewise Threat Intelligence

CVE-2026-37236: grpc-gateway incorrect access control in X-HTTP-Method-Override

CVE-2026-37236 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Executive brief

grpc-gateway is a proxy service that converts HTTP requests into gRPC calls. A vulnerability allows attackers to bypass method-based access controls by spoofing the HTTP request method via the X-HTTP-Method-Override header, potentially gaining unauthorized access to protected endpoints or bypassing security policies enforced by upstream firewalls and WAF systems.

Technical details

grpc-gateway v2.28.0 processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without proper validation or restrictions. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing, allowing method-based access control bypasses. The vulnerability affects any deployment where method-level authorization checks are enforced by upstream proxies, WAFs, or the gateway itself. A fix is available via the WithDisableHTTPMethodOverride ServeMux option, which allows disabling header-based method override independently of other features.

Affected products

  • grpc-ecosystem grpc-gateway 2.28.0

Timeline

  • 2026-08-28: disclosed

References