CVE-2026-41491

Source
https://cve.org/CVERecord?id=CVE-2026-41491
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41491.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41491
Aliases
Downstream
Related
Published
2026-05-08T13:11:13Z
Modified
2026-08-12T03:51:31Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Dapr: Service Invocation path traversal ACL bypass
Details

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-rc.1 to before 1.16.14, and 1.17.0-rc.1 to before 1.17.5, a vulnerability has been found in Dapr that allows bypassing access control policies for service invocation using reserved URL characters and path traversal sequences in method paths. The ACL normalized the method path independently from the dispatch layer, so the ACL evaluated one path while the target application received a different one. This issue has been patched in versions 1.15.14, 1.16.14, and 1.17.5.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22",
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41491.json"
}
References

Affected packages

Git / github.com/dapr/dapr

Affected ranges

Type
GIT
Repo
https://github.com/dapr/dapr
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:linuxfoundation:dapr:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.3.0"
        },
        {
            "fixed": "1.15.14"
        },
        {
            "introduced": "1.16.0"
        },
        {
            "fixed": "1.16.14"
        },
        {
            "introduced": "1.17.0"
        },
        {
            "fixed": "1.17.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v1.*
v1.16.0
v1.16.1-rc.1
v1.16.1-rc.2
v1.16.1-rc.3
v1.16.10
v1.16.11
v1.16.11-rc.1
v1.16.11-rc.2
v1.16.11-rc.3
v1.16.12
v1.16.12-rc.1
v1.16.13
v1.16.13-rc.1
v1.16.2
v1.16.2-rc.1
v1.16.2-rc.2
v1.16.3
v1.16.4
v1.16.5
v1.16.6
v1.16.7
v1.16.7-rc.1
v1.16.8
v1.16.9
v1.16.9-rc.1
v1.17.0
v1.17.1
v1.17.1-rc.1
v1.17.2
v1.17.2-rc.1
v1.17.2-rc.2
v1.17.2-rc.3
v1.17.3
v1.17.3-rc.1
v1.17.3-rc.2
v1.17.4
v1.17.4-rc.1
v1.17.4-rc.2
v1.17.4-rc.3
v1.17.4-rc.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41491.json"