Executive brief
grpc-gateway is a proxy service that converts HTTP requests into gRPC calls. A vulnerability allows attackers to bypass method-based access controls by spoofing the HTTP request method via the X-HTTP-Method-Override header, potentially gaining unauthorized access to protected endpoints or bypassing security policies enforced by upstream firewalls and WAF systems.
Technical details
grpc-gateway v2.28.0 processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without proper validation or restrictions. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing, allowing method-based access control bypasses. The vulnerability affects any deployment where method-level authorization checks are enforced by upstream proxies, WAFs, or the gateway itself. A fix is available via the WithDisableHTTPMethodOverride ServeMux option, which allows disabling header-based method override independently of other features.
Affected products
- grpc-ecosystem grpc-gateway 2.28.0
Timeline
- 2026-08-28: disclosed