Impact
gRPC-Go is the Go implementation of gRPC. In versions before 1.82.2 and 1.83.2, a server created with xds.NewGRPCServer() allowed an RPC that omitted both the :authority and Host headers. Internally, the request is forwarded from internal/transport/http2_server.go to internal/xds/server/routing.go, where code assumes an authority value exists and indexes into that slice. Because the slice is empty, an index‑out‑of‑bounds panic occurs, which is not recovered by the per‑RPC goroutine and brings down the whole process, resulting in a denial of service. The flaw constitutes an out‑of‑bounds array access (CWE‑125), a slice index error without bounds checking (CWE‑129), and a missing required header field (CWE‑248). A remote client that can establish a transport connection to the xDS endpoint can trigger the crash. In insecure or ordinary TLS deployments the request may be unauthenticated, whereas strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC reaches an interceptor.
Affected Systems
The issue affects the grpc-go implementation for the Go programming language. Versions prior to 1.82.2 and 1.83.2 are vulnerable when servers are created with xds.NewGRPCServer(). Any deployment using those versions that exposes an xDS endpoint is susceptible, regardless of the product that embeds grpc-go.
Risk and Exploitability
The CVSS score of 8.7 marks this flaw as high impact. EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been documented. A remote attacker that can establish a transport connection to the xDS server may send an RPC missing the required headers, provoking the out‑of‑bounds panic and crashing the entire process. In insecure or ordinary TLS deployments the request may be unauthenticated; in strict mTLS or ALTS deployments, valid transport credentials are required before the malformed RPC reaches the interceptor.
OpenCVE Enrichment
Github GHSA