GHSA-2v4p-qf9q-27wj: gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
HIGHHigh-risk vulnerability
A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS). Servers built with `xds.NewGRPCServer` install an xDS routing interceptor on every RPC. This interceptor looks up the request’s `:authority` header to pick a virtual host. The HTTP/2 server transport previously accepted requests that had neither `:authority` nor `Host`. …
CVE · detail
- CVE-2026-84445nvd ↗EPSS 0.69%
● loading threat intel…
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected