[GHSA-2v4p-qf9q-27wj] gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing :authority and Host headers - #9658
Conversation
|
Hi there @easwars! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Removing the full development range incorrectly marks vulnerable prerelease and pseudo-versions as unaffected.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
What changed in this PR
Updates the gRPC-Go advisory’s affected-version metadata to recognize v1.84.0 as fixed.
Changes:
- Removes the existing development-version affected range.
- Updates the advisory modification timestamp.
| File | Description |
|---|---|
GHSA-2v4p-qf9q-27wj.json |
Revises affected gRPC-Go versions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| ] | ||
| } | ||
| ] | ||
| } |

Updates
Comments
Appears fixed in 1.84.0
See grpc/grpc-go#9370