THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2v4p-qf9q-27wj (high) — gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

[GHSA] GHSA-2v4p-qf9q-27wj (high) — gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

medgithub_advisoriesPublished 2026-09-08

GHSA-2v4p-qf9q-27wj Severity: high CVE: CVE-2026-84445

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS).

Servers built with `xds.N

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2v4p-qf9q-27wj