CVE-2026-84445: gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers in the xDS servers

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-Sep
Released
2026-09-16
Last Updated
2026-09-17
EPSS Score
0.69% (percentile: 50.9%)

Affected Products (33)

Other

  • 21853-17084
  • 21854-17084
  • 21826-17084
  • 21768-17084
  • 21827-17084
  • 21828-17084
  • 21647-17084
  • 21687-17084
  • 21770-17084
  • 21743-17084
  • 21856-17084
  • 21682-17084
  • 21830-17084
  • 21825-17084
  • 21796-17084
  • 21816-17084
  • 21813-17084
  • 21842-17084
  • 21831-17084
  • 21833-17084
  • 21832-17084
  • 21835-17084
  • 21705-17084
  • 21807-17084
  • 21797-17084
  • 21772-17084
  • 21814-17084
  • 21834-17084
  • 21798-17084
  • 21799-17084
  • 21836-17084
  • 21858-17084
  • 21771-17084

Security Updates (1)

Revision History

  • 2026-09-16: Information published.
  • 2026-09-17: Information published.