gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers in the xDS servers (CVE-2026-84445) | HOL Guard CVE