PoC Archive PoC Archive

tag

Grpc

Critical
RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926)
CVE-2025-68926· RustFS (Rust-based S3-compatible distributed object storage) — internal node-to-node gRPC service unpatched
High
gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)
CVE-2026-33186 (GHSA-p77j-4mvh-x3m3)· google.golang.org/grpc (grpc-go) authz package (SDK-level RBAC) patched
Critical
Feast Registry gRPC Unauthenticated RCE via dill.loads — CVE-2026-56121
CVE-2026-56121· Feast (open-source feature store) registry gRPC server patched