VDB

CVE-2026-84445

CVE-2026-84445 PUBLISHED CVSS 8.7 HIGH

Reported by GitHub_M · Published September 14, 2026

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.

Risk Scores

CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
grpcgrpc-go< 1.82.2, >= 1.83.0, < 1.83.2
wolfikserve0, 0
chainguardtemporal-server-1.300
chainguardgcp-compute-persistent-disk-csi-driver-fips-1.140
chainguardgatekeeper-3.230, 0
wolfimigrate0, 0, 0
chainguardconsul-1.220
chainguardcrossplane-provider-aws-codeartifact0
chainguardargo-workflows-4.00
chainguardlonghorn-manager-fips-1.100, 0
chainguardconsul-k8s-fips-2.00
chainguarddatadog-operator-fips0, 0
chainguardcrossplane-provider-aws-imagebuilder-fips0
chainguardmc0, 0
chainguardflagger0, 0
chainguardlivekit-server0, 0
chainguardamass0
chainguardknative-serving-fips-1.220, 0
chainguardsftpgo-plugin-auth0
chainguardnifikop-fips0, 0

…and 2347 more

Timeline

  • Sep 4, 2026 CVE Published
  • Sep 9, 2026 Security Advisory
  • Sep 15, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 17, 2026 CVE Updated
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›