#1149961 golang-google-grpc: CVE-2026-84445

Package:
src:golang-google-grpc
Source:
src:golang-google-grpc
Submitter:
Salvatore Bonaccorso
Date:
2026-10-04 19:15:03 UTC
Severity:
normal
Tags:
#1149961#5
Date:
2026-10-04 19:12:32 UTC
From:
To:
Hi,

The following vulnerability was published for golang-google-grpc.

CVE-2026-84445[0]:
| gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2
| and 1.83.2, servers created with xds.NewGRPCServer() allow
| internal/transport/http2_server.go to accept an RPC containing
| neither the :authority header nor the Host header, while
| RouteAndProcess in internal/xds/server/routing.go assumes that an
| authority value exists and indexes the empty slice. A remote client
| that can complete transport connection establishment can trigger an
| index-out-of-bounds panic that is not recovered by the per-RPC
| goroutine and terminates the entire server process. In insecure or
| ordinary TLS deployments the request can be unauthenticated, while
| strict mTLS or ALTS deployments require valid transport credentials
| before the malformed RPC can reach the interceptor. This issue is
| fixed in versions 1.82.2 and 1.83.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-84445
https://www.cve.org/CVERecord?id=CVE-2026-84445
[1] https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj
[2] https://github.com/grpc/grpc-go/issues/9354
[3] https://github.com/grpc/grpc-go/pull/9367
[4] https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore