tag
Grpc
Critical
RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926)
CVE-2025-68926·
RustFS (Rust-based S3-compatible distributed object storage) — internal node-to-node gRPC service
unpatched
High
gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)
CVE-2026-33186 (GHSA-p77j-4mvh-x3m3)·
google.golang.org/grpc (grpc-go) authz package (SDK-level RBAC)
patched
Critical
Feast Registry gRPC Unauthenticated RCE via dill.loads — CVE-2026-56121
CVE-2026-56121·
Feast (open-source feature store) registry gRPC server
patched