GO-2024-2978: Private tokens could appear in logs if context containing gRPC metadata is logged in google.golang.org/grpc
GO-2026-4762: Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc
GO-2026-6061: Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
GO-2026-6348: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc
GO-2026-6441: Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc
GO-2026-6443: Server panic via missing authority or Host headers in google.golang.org/grpc