CVE-2026-33186

Releases whose notes mention this CVE, found verbatim in the text — 7 releases so far. The vulnerability itself is described in the National Vulnerability Database. Or browse all security updates.

Releases mentioning CVE-2026-33186

Netdata

Netdata · Infrastructure & DevOps

Network Monitor Dashboard (Technical Preview) with device inventory, metrics, topology, flows, traps and alerts; Network Flows collection for NetFlow, IPFIX and sFlow from…

AddedChangedDeprecated

GitLab Runner

GitLab · Infrastructure & DevOps

Add Snowplow writer for usage-based billing; Add nanoserver:ltsc2025 and nanoserver:ltsc2025-arm64 helper images; Add native steps support to the instance executor; Add ability to…

AddedFixedSecurity

Portainer

Portainer · Infrastructure & DevOps

Fixed a Docker API proxy authorisation bypass that allowed regular users to circumvent deny-plugin restrictions; Changed a default setting to enforce server-side EdgeID on first…

AddedChangedFixedRemovedSecurity

Consul

HashiCorp · Infrastructure & DevOps

Update google.golang.org/grpc to fix CVE-2026-33186; Upgrade go.opentelemetry.io/otel to 1.42.0 to remediate CVE-2026-24051 (Path Hijacking / Untrusted Search Paths on macOS)…

AddedChangedFixedSecurity

Consul

HashiCorp · Infrastructure & DevOps

Upgrade Envoy version to 1.35.9 and 1.34.13; Update google.golang.org/grpc to fix CVE-2026-33186; Upgrade Go version to 1.25.8; Bump golang.org/x/ dependencies to align with…

AddedChangedFixedSecurity

rclone

rclone · System Utilities

Update to google.golang.org/grpc 1.79.3 to fix CVE-2026-33186; Update to github.com/buger/jsonparser 1.1.2 to fix GHSA-6g7g-w4f8-9c9x; Fix URLPathEscapeAll breaking WebDAV servers…

FixedSecurity

livekit

livekit · Infrastructure & DevOps

Add option to require media sections when participant joining; Support originating calls from custom domains; Add StopEgress function to the EgressLauncher interface; Add option…

AddedChangedFixed