VDB

CVE-2026-84303

CVE-2026-84303 PUBLISHED CVSS 6.3 MEDIUM

Reported by GitHub_M · Published September 1, 2026

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.

Risk Scores

CVSS 4.0
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
grpcgrpc-go< 1.83.1
chainguardkubernetes-csi-external-resizer0
chainguardknative-serving-1.210
wolfidatadog-agent-7.780
chainguardcadence*
chainguardipfs-cluster0
chainguarddatadog-agent-7.810
chainguardcommercial-nginx-ingress0, 0
wolficloud-provider-vsphere0, 0
chainguardk8ssandra-client0
chainguardamazon-cloudwatch-agent0
wolfidatadog-agent-7.760, 0, 0
chainguardnet-kourier-fips-1.200
chainguarddatadog-agent-fips-7.790
chainguardgcp-compute-persistent-disk-csi-driver-fips-1.170, 0
chainguarddapr-1.150
wolfirancher-agent-2.130, 0
chainguarddapr-fips-1.160
chainguardcommercial-grafana-13.00
wolfikubeflow-pipelines0, 0

…and 140 more

Timeline

  • Sep 1, 2026 Coalition ESS Score
  • Sep 1, 2026 CVE Published
  • Sep 2, 2026 EPSS Score
  • Sep 2, 2026 CVE Updated
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 9, 2026 Security Advisory
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›