THREAT OPS › Threat News › [GHSA] GHSA-2v4p-qf9q-27wj (high) — gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
[GHSA] GHSA-2v4p-qf9q-27wj (high) — gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
GHSA-2v4p-qf9q-27wj Severity: high CVE: CVE-2026-84445
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS).
Servers built with `xds.N
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-84445cve
Original source: https://github.com/advisories/GHSA-2v4p-qf9q-27wj