CVE-2026-84445

high

Description

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.

References

https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj

https://github.com/grpc/grpc-go/releases/tag/v1.83.2

https://github.com/grpc/grpc-go/releases/tag/v1.82.2

https://github.com/grpc/grpc-go/pull/9367

https://github.com/grpc/grpc-go/pull/9366

https://github.com/grpc/grpc-go/pull/9365

https://github.com/grpc/grpc-go/issues/9354

https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f

https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4

https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77627

Details

Source: Mitre, NVD

Published: 2026-09-14

Updated: 2026-09-25

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High

CVSS v4

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00685