Skip to content
archivevulnerability · 08 Sep 2026 · 21:21 UTC

GHSA-2v4p-qf9q-27wj: gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

VULNCVE-2026-84445source · GTH
HIGHHigh-risk vulnerability

last 60 dispatches · spectrum

A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS). Servers built with `xds.NewGRPCServer` install an xDS routing interceptor on every RPC. This interceptor looks up the request’s `:authority` header to pick a virtual host. The HTTP/2 server transport previously accepted requests that had neither `:authority` nor `Host`. …

CVE · detail
grounded ✓primary source ↗

loading threat intel…

Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected