Uncaught Exception in grpc-go - #VU144261

 

Uncaught Exception in grpc-go - #VU144261

Published: August 19, 2026


Vulnerability identifier: #VU144261
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of exceptional conditions in the xDS RBAC policy translator when parsing crafted xDS RBAC policies containing NOT rules around unsupported fields. A remote attacker can deliver a crafted LDS or RDS update to cause a denial of service.

The issue occurs when a NOT rule wraps an unsupported or unhandled field such as SourcedMetadata, which can produce an empty matcher and trigger a runtime panic during authorization of an incoming request.


Affected software

grpc-go

Remediation

Install security update from vendor's website.

grpc-go - update to 1.82.1

External References

Related Security Bulletins