Description
gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (DoS) via server crash
Action: Immediate Patch
AI Analysis

Impact

gRPC-Go is the Go implementation of gRPC. In versions before 1.82.2 and 1.83.2, a server created with xds.NewGRPCServer() allowed an RPC that omitted both the :authority and Host headers. Internally, the request is forwarded from internal/transport/http2_server.go to internal/xds/server/routing.go, where code assumes an authority value exists and indexes into that slice. Because the slice is empty, an index‑out‑of‑bounds panic occurs, which is not recovered by the per‑RPC goroutine and brings down the whole process, resulting in a denial of service. The flaw constitutes an out‑of‑bounds array access (CWE‑125), a slice index error without bounds checking (CWE‑129), and a missing required header field (CWE‑248). A remote client that can establish a transport connection to the xDS endpoint can trigger the crash. In insecure or ordinary TLS deployments the request may be unauthenticated, whereas strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC reaches an interceptor.

Affected Systems

The issue affects the grpc-go implementation for the Go programming language. Versions prior to 1.82.2 and 1.83.2 are vulnerable when servers are created with xds.NewGRPCServer(). Any deployment using those versions that exposes an xDS endpoint is susceptible, regardless of the product that embeds grpc-go.

Risk and Exploitability

The CVSS score of 8.7 marks this flaw as high impact. EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been documented. A remote attacker that can establish a transport connection to the xDS server may send an RPC missing the required headers, provoking the out‑of‑bounds panic and crashing the entire process. In insecure or ordinary TLS deployments the request may be unauthenticated; in strict mTLS or ALTS deployments, valid transport credentials are required before the malformed RPC reaches the interceptor.

Generated by OpenCVE AI on September 21, 2026 at 00:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade grpc-go to v1.82.2 or later, or to v1.83.2 or later if using that release line
  • Restrict network access to the xDS endpoint, limiting connections to trusted hosts or networks with firewalls or segmentation
  • Configure application monitoring to detect sudden crashes and restart the process, applying the patch as soon as it becomes available

Generated by OpenCVE AI on September 21, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2v4p-qf9q-27wj gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
History

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Grpc
Grpc grpc-go
Vendors & Products Grpc
Grpc grpc-go

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.
Title gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers in the xDS servers
Weaknesses CWE-129
CWE-248
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:36:14.966Z

Reserved: 2026-09-01T20:05:09.422Z

Link: CVE-2026-84445

cve-icon Vulnrichment

Updated: 2026-09-14T16:36:09.428Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T17:17:51.743

Modified: 2026-09-25T14:10:13.927

Link: CVE-2026-84445

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T16:11:41Z

Links: CVE-2026-84445 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses