VDB
CVE-2026-84303
CVE-2026-84303
PUBLISHED
CVSS 6.3 MEDIUM
Reported by GitHub_M · Published September 1, 2026
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.
Risk Scores
CVSS 4.0
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| grpc | grpc-go | < 1.83.1 |
| chainguard | kubernetes-csi-external-resizer | 0 |
| chainguard | knative-serving-1.21 | 0 |
| wolfi | datadog-agent-7.78 | 0 |
| chainguard | cadence | * |
| chainguard | ipfs-cluster | 0 |
| chainguard | datadog-agent-7.81 | 0 |
| chainguard | commercial-nginx-ingress | 0, 0 |
| wolfi | cloud-provider-vsphere | 0, 0 |
| chainguard | k8ssandra-client | 0 |
| chainguard | amazon-cloudwatch-agent | 0 |
| wolfi | datadog-agent-7.76 | 0, 0, 0 |
| chainguard | net-kourier-fips-1.20 | 0 |
| chainguard | datadog-agent-fips-7.79 | 0 |
| chainguard | gcp-compute-persistent-disk-csi-driver-fips-1.17 | 0, 0 |
| chainguard | dapr-1.15 | 0 |
| wolfi | rancher-agent-2.13 | 0, 0 |
| chainguard | dapr-fips-1.16 | 0 |
| chainguard | commercial-grafana-13.0 | 0 |
| wolfi | kubeflow-pipelines | 0, 0 |
…and 140 more
Timeline
- Sep 1, 2026 Coalition ESS Score
- Sep 1, 2026 CVE Published
- Sep 2, 2026 EPSS Score
- Sep 2, 2026 CVE Updated
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 9, 2026 Security Advisory
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3 x_refsource_CONFIRM
- https://github.com/grpc/grpc-go/pull/9332 x_refsource_MISC
- https://github.com/grpc/grpc-go/pull/9335 x_refsource_MISC
- https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8 x_refsource_MISC
- https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe x_refsource_MISC
- https://github.com/grpc/grpc-go/releases/tag/v1.83.1 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-84303 advisory
- https://github.com/advisories/GHSA-qc2q-p7wx-3px3 advisory