CVE-2026-84445

EUVD-2026-77627
gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
golang-google-grpc
bookworm
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-googlecloudplatform-grpc-gcp-go
jammy
dne
noble
dne
resolute
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
azure-storage-azcopy
suse enterprise server 15 SP4
10.32.8-150400.9.21.1
fixed
google-cloud-sap-agent
suse enterprise sap 12
3.15-6.81.1
fixed
suse enterprise sap 12 SP3
3.15-6.81.1
fixed
suse enterprise sap 12 SP4
3.15-6.81.1
fixed
suse enterprise sap 12 SP5
3.15-6.81.1
fixed
suse enterprise server 12
3.15-6.81.1
fixed
suse enterprise server 12 SP3
3.15-6.81.1
fixed
suse enterprise server 12 SP4
3.15-6.81.1
fixed
suse enterprise server 12 SP5
3.15-6.81.1
fixed
helm
suse enterprise sap 15 SP4
3.21.3-150000.1.96.1
fixed
suse enterprise sap 15 SP5
3.21.3-150000.1.96.1
fixed
suse enterprise sap 15 SP6
3.21.3-150000.1.96.1
fixed
suse enterprise sap 15 SP7
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP4
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP5
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP6
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP7
3.21.3-150000.1.96.1
fixed
helm-bash-completion
suse enterprise sap 15 SP4
3.21.3-150000.1.96.1
fixed
suse enterprise sap 15 SP5
3.21.3-150000.1.96.1
fixed
suse enterprise sap 15 SP6
3.21.3-150000.1.96.1
fixed
suse enterprise sap 15 SP7
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP4
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP5
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP6
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP7
3.21.3-150000.1.96.1
fixed
helm-zsh-completion
suse enterprise sap 15 SP4
3.21.3-150000.1.96.1
fixed
suse enterprise sap 15 SP5
3.21.3-150000.1.96.1
fixed
suse enterprise sap 15 SP6
3.21.3-150000.1.96.1
fixed
suse enterprise sap 15 SP7
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP4
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP5
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP6
3.21.3-150000.1.96.1
fixed
suse enterprise server 15 SP7
3.21.3-150000.1.96.1
fixed