[GH-ISSUE #5632] [Security] Affected by CVE-2026-33186 ? #11817

Open
opened 2026-08-05 01:31:09 -04:00 by saavagebueno · 2 comments
Owner

Originally created by @Bloopps on GitHub (Mar 19, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5632

I think the latest version of Netbird is affected by the CVE-2026-33186

google.golang.org/grpc v1.77.0

Can you confirm this?

Originally created by @Bloopps on GitHub (Mar 19, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5632 I think the latest version of Netbird is affected by the CVE-2026-33186 [google.golang.org/grpc v1.77.0](https://github.com/netbirdio/netbird/blob/5ffaa5cdd622c8def65134d3f593e4d7d23e3bc5/go.mod#L25) Can you confirm this?
Author
Owner

@hrfried commented on GitHub (Mar 26, 2026):

Would appreciate a response on this, considering it's a 9.1/10 critical CVE as per the NVD:
https://nvd.nist.gov/vuln/detail/CVE-2026-33186

<!-- gh-comment-id:4138053567 --> @hrfried commented on GitHub (Mar 26, 2026): Would appreciate a response on this, considering it's a 9.1/10 critical CVE as per the NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-33186
Author
Owner

@braginini commented on GitHub (Mar 27, 2026):

@Bloopps @hrfried

NetBird is not affected by this as we don't use gRPC interceptor/middleware, etc, and handle auth on our own.

Though we will update to the latest version in the next release.

<!-- gh-comment-id:4141410699 --> @braginini commented on GitHub (Mar 27, 2026): @Bloopps @hrfried NetBird is not affected by this as we don't use gRPC interceptor/middleware, etc, and handle auth on our own. Though we will update to the latest version in the next release.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#11817