StackRadar

CVE-2026-33186

Critical

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,640
of 17,790 indexed, latest versions
Container images
1,989
deployed by those charts
Fix available
1 of 1
affected package

gRPC-Go has an authorization bypass via missing leading slash in :path

Carried by container images the latest versions of 1,640 of 17,790 indexed charts deploy, on 1,989 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+107 more1.79.31,989
OSV records
GHSA-p77j-4mvh-x3m3
Also known as
GO-2026-4762

Charts affected

1,640 by stars
ChartLatestAffected imagesRadar Score
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
inaccel/daemon:latest093e1ea90ab8
google.golang.org/grpc@v1.61.0
1.79.3

Open the chart page →

5,759
iomeshkubesphere-stable1.1.017 of 25See more

iomesh kubesphere-stable 1.1.0

17 of the 25 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-driver:v2.7.25d3f9bf9240b
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
google.golang.org/grpc@v1.40.0
1.79.3
iomesh/csi-provisioner:v3.0.0f9508460b273
google.golang.org/grpc@v1.38.0
1.79.3
iomesh/csi-snapshotter:v6.2.2becc53e25b96
google.golang.org/grpc@v1.50.1
1.79.3
iomesh/deck:v0.1.0a31e26b6ae22
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/livenessprobe:v2.8.0560f01510f99
google.golang.org/grpc@v1.48.0
1.79.3
iomesh/localpv-manager:v0.2.0f13deacac3f4
google.golang.org/grpc@v1.50.0
1.79.3
iomesh/node-disk-manager:1.8.0002c4b92fd34
google.golang.org/grpc@v1.27.1
1.79.3
iomesh/operator:v1.1.060081c9b2f52
google.golang.org/grpc@v1.41.0
1.79.3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
google.golang.org/grpc@v1.51.0
1.79.3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
google.golang.org/grpc@v1.51.0
1.79.3

Open the chart page →

48,833
IOMeshkubesphere-stable1.2.017 of 25See more

IOMesh kubesphere-stable 1.2.0

17 of the 25 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-driver:v2.8.01a151f602451
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
google.golang.org/grpc@v1.40.0
1.79.3
iomesh/csi-provisioner:v3.0.0f9508460b273
google.golang.org/grpc@v1.38.0
1.79.3
iomesh/csi-snapshotter:v6.2.2becc53e25b96
google.golang.org/grpc@v1.50.1
1.79.3
iomesh/deck:v0.2.0282d6c419ed3
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/livenessprobe:v2.8.0560f01510f99
google.golang.org/grpc@v1.48.0
1.79.3
iomesh/localpv-manager:v0.2.0f13deacac3f4
google.golang.org/grpc@v1.50.0
1.79.3
iomesh/node-disk-manager:1.8.0-2292ad270082e
google.golang.org/grpc@v1.27.1
1.79.3
iomesh/operator:v1.2.0ba4dd6be7e59
google.golang.org/grpc@v1.41.0
1.79.3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
google.golang.org/grpc@v1.51.0
1.79.3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
google.golang.org/grpc@v1.51.0
1.79.3

Open the chart page →

46,507
pulsarkubesphere-stable2.7.132 of 3See more

pulsar kubesphere-stable 2.7.13

2 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
google.golang.org/grpc@v1.27.1
1.79.3
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
google.golang.org/grpc@v1.35.0
1.79.3

Open the chart page →

14,368
aws-fsx-csi-driverkubesphere-testVerified publisher0.1.01 of 4See more

aws-fsx-csi-driver kubesphere-test 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
amazon/aws-fsx-csi-driver:latestc9b14856fd22
google.golang.org/grpc@v1.23.1
1.79.3

Open the chart page →

1,588
cni-hostnickubesphere-testVerified publisher0.1.01 of 1See more

cni-hostnic kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
google.golang.org/grpc@v1.27.1
1.79.3

Open the chart page →

2,437
csi-neonsankubesphere-testVerified publisher1.3.06 of 6See more

csi-neonsan kubesphere-test 1.3.0

6 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-neonsan:v1.2.21fa83d45417f
google.golang.org/grpc@v1.26.0
1.79.3
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
google.golang.org/grpc@v1.34.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/grpc@v1.36.0
1.79.3

Open the chart page →

18,482
csi-qingcloudkubesphere-testVerified publisher1.4.06 of 6See more

csi-qingcloud kubesphere-test 1.4.0

6 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-qingcloud:v1.4.00766163dc046
google.golang.org/grpc@v1.26.0
1.79.3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
google.golang.org/grpc@v1.34.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/grpc@v1.36.0
1.79.3

Open the chart page →

12,404
curvefs-csikubesphere-testVerified publisher0.1.01 of 3See more

curvefs-csi kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
google.golang.org/grpc@v1.10.0
1.79.3

Open the chart page →

2,824
minio-gatewaykubesphere-testVerified publisher0.1.01 of 1See more

minio-gateway kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
google.golang.org/grpc@v1.71.0
1.79.3

Open the chart page →

1,069
online-boutiquekubesphere-testVerified publisher0.1.08 of 11See more

online-boutique kubesphere-test 0.1.0

8 of the 11 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
google.golang.org/grpc@v1.22.0
1.79.3
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
google.golang.org/grpc@v1.22.0
1.79.3
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
google.golang.org/grpc@v1.22.0
1.79.3
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
google.golang.org/grpc@v1.22.0
1.79.3

Open the chart page →

26,019
openelbkubesphere-testVerified publisher0.2.41 of 2See more

openelb kubesphere-test 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
google.golang.org/grpc@v1.26.0
1.79.3

Open the chart page →

4,329
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
google.golang.org/grpc@v1.26.0
1.79.3

Open the chart page →

2,784
kubestellar-consolekubestellar-consoleVerified publisher0.3.411 of 2See more

kubestellar-console kubestellar-console 0.3.41

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
alpine/k8s:1.32.47e1e7d5b7a96
google.golang.org/grpc@v1.68.0
1.79.3

Open the chart page →

4,440
kubestellar-uikubestellaruiVerified publisher0.1.11 of 4See more

kubestellar-ui kubestellarui 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
mavrick1/kubestellar-b:latest45ca0429a1d4
google.golang.org/grpc@v1.53.0
1.79.3

Open the chart page →

4,763
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.43 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

3 of the 9 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
google.golang.org/grpc@v1.67.1
1.79.3
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
google.golang.org/grpc@v1.65.0
1.79.3
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
google.golang.org/grpc@v1.73.0
1.79.3

Open the chart page →

20,299
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
google.golang.org/grpc@v1.49.0
1.79.3

Open the chart page →

3,460
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
google.golang.org/grpc@v1.69.0
1.79.3

Open the chart page →

6,879
dynatrace-operatorkvalitetsitVerified publisher1.3.01 of 1See more

dynatrace-operator kvalitetsit 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
google.golang.org/grpc@v1.65.0
1.79.3

Open the chart page →

1,313
krakendkvalitetsitVerified publisher0.0.31 of 1See more

krakend kvalitetsit 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
devopsfaith/krakend:latestf8bdaa8a1a43
google.golang.org/grpc@v1.66.0
1.79.3

Open the chart page →

1,242
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
google.golang.org/grpc@v1.23.0
1.79.3

Open the chart page →

16,537
metadockvalitetsitVerified publisher0.0.71 of 2See more

metadoc kvalitetsit 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-web:mainf57e7553f5bd
google.golang.org/grpc@v1.37.0
1.79.3

Open the chart page →

4,026
openidkvalitetsitVerified publisher1.7.21 of 2See more

openid kvalitetsit 1.7.2

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.14.368336da945bd
google.golang.org/grpc@v1.78.0
1.79.3

Open the chart page →

586
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

8,534
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

26,371
lagoon-docker-hostlagoon-chartsVerified publisher0.7.01 of 1See more

lagoon-docker-host lagoon-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
google.golang.org/grpc@v1.69.4
1.79.3

Open the chart page →

2,113
lambdapinglambdaping1.0.41 of 1See more

lambdaping lambdaping 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
udhos/lambdaping:1.0.46bd2cf2ac732
google.golang.org/grpc@v1.69.2
1.79.3

Open the chart page →

1,330
cachelavaOfficialVerified publisher1.1.11 of 1See more

cache lava 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
google.golang.org/grpc@v1.62.1
1.79.3

Open the chart page →

1,378
pinglbenicio-communityVerified publisher0.1.11 of 1See more

ping lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
google.golang.org/grpc@v1.77.0
1.79.3

Open the chart page →

594
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
google.golang.org/grpc@v1.72.2
1.79.3

Open the chart page →

32,893
prometheuslectures-k8sinfra15.8.51 of 6See more

prometheus lectures-k8sinfra 15.8.5

1 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
google.golang.org/grpc@v1.47.0
1.79.3

Open the chart page →

9,092
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
google.golang.org/grpc@v1.27.1
1.79.3

Open the chart page →

3,191
prometheusleechistest11.6.01 of 6See more

prometheus leechistest 11.6.0

1 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
google.golang.org/grpc@v1.29.1
1.79.3

Open the chart page →

8,484
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
google.golang.org/grpc@v1.49.0
1.79.3

Open the chart page →

4,271
minioleprechaun-charts0.1.61 of 1See more

minio leprechaun-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-01-20T14-49-07Z-cpuv114b7076ca85a
google.golang.org/grpc@v1.69.2
1.79.3

Open the chart page →

1,312
kltlifecycle-toolkitOfficialVerified publisher0.2.63 of 4See more

klt lifecycle-toolkit 0.2.6

3 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/keptn/lifecycle-operator:v0.8.2487bfc37c4b4
google.golang.org/grpc@v1.57.0
1.79.3
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
google.golang.org/grpc@v1.52.3
1.79.3
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
google.golang.org/grpc@v1.57.0
1.79.3

Open the chart page →

4,659
lightsteplightstep-microsat2.0.211 of 1See more

lightstep lightstep-microsat 2.0.21

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
google.golang.org/grpc@v1.61.0
1.79.3

Open the chart page →

1,116
linkerd-preview-vizlinkerd-buoyantVerified publisher25.4.34 of 5See more

linkerd-preview-viz linkerd-buoyant 25.4.3

4 of the 5 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
google.golang.org/grpc@v1.71.1
1.79.3
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
google.golang.org/grpc@v1.66.0
1.79.3
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
google.golang.org/grpc@v1.71.1
1.79.3
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
google.golang.org/grpc@v1.71.1
1.79.3

Open the chart page →

3,420
linkerd-dashboardlinkerd-dashboardOfficial0.11.11 of 2See more

linkerd-dashboard linkerd-dashboard 0.11.1

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
google.golang.org/grpc@v1.71.0
1.79.3

Open the chart page →

1,037
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.44 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

4 of the 5 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
google.golang.org/grpc@v1.72.2
1.79.3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
google.golang.org/grpc@v1.78.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
google.golang.org/grpc@v1.79.1
1.79.3
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.79.3

Open the chart page →

2,933
liqo-upgrade-operatorliqo-upgrade-operatorVerified publisher0.1.01 of 1See more

liqo-upgrade-operator liqo-upgrade-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kazem26/liqo-upgrade-operator:v0.1268b7c6a59dd
google.golang.org/grpc@v1.72.1
1.79.3

Open the chart page →

368
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
google.golang.org/grpc@v1.60.1
1.79.3

Open the chart page →

10,773
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
google.golang.org/grpc@v1.42.0
1.79.3

Open the chart page →

2,129
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
google.golang.org/grpc@v1.72.2
1.79.3

Open the chart page →

1,553
llmarinerllmariner1.53.112 of 21See more

llmariner llmariner 1.53.1

12 of the 21 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
google.golang.org/grpc@v1.67.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
google.golang.org/grpc@v1.68.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
google.golang.org/grpc@v1.73.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/inference-manager-server:1.45.090b890f800ab
google.golang.org/grpc@v1.67.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
google.golang.org/grpc@v1.67.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/user-manager-server:1.27.1628a14449241
google.golang.org/grpc@v1.67.0
1.79.3

Open the chart page →

12,034
llm-dllm-dVerified publisher1.0.231 of 2See more

llm-d llm-d 1.0.23

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
google.golang.org/grpc@v1.71.1
1.79.3

Open the chart page →

2,524
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
google.golang.org/grpc@v1.63.2
1.79.3

Open the chart page →

2,155
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

4,904
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
google.golang.org/grpc@v1.56.2
1.79.3

Open the chart page →

2,101
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
google.golang.org/grpc@v1.65.0
1.79.3

Open the chart page →

2,020

Container images carrying it

1,989 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dragonflyoss/client:v0.1.82edf3e921f4e0
google.golang.org/grpc@v1.60.1
1.79.3
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
google.golang.org/grpc@v1.64.0
1.79.3
1
dragonflyoss/scheduler:v2.1.49523785c77787
google.golang.org/grpc@v1.64.0
1.79.3
1
drone/drone:2.28.255897c8fb22d
google.golang.org/grpc@v1.59.0
1.79.3
1
drone/drone-runner-docker:1.8.1137e79c5e23c
google.golang.org/grpc@v1.29.1
1.79.3
1
drumsergio/duplicacy-container:0.1.0dd3ee9703969
google.golang.org/grpc@v1.28.1
1.79.3
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/grpc@v1.49.0
1.79.3
1
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
google.golang.org/grpc@v1.56.3
1.79.3
1
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
google.golang.org/grpc@v1.40.0
1.79.3
1
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
google.golang.org/grpc@v1.27.0
1.79.3
1
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
google.golang.org/grpc@v1.68.1
1.79.3
1
elastic/apm-server:7.17.6c7a1c63257d0
google.golang.org/grpc@v1.48.0
1.79.3
1
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
google.golang.org/grpc@v1.68.1
1.79.3
1
emqx/ecp-main:2.5.1fa876f71e5d6
google.golang.org/grpc@v1.67.1
1.79.3
1
emqxecp/otelcol:2.5.04c31d9bec846
google.golang.org/grpc@v1.66.0
1.79.3
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
google.golang.org/grpc@v1.31.0
1.79.3
1
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
google.golang.org/grpc@v1.74.2
1.79.3
1
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/grpc@v1.56.2
1.79.3
1
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
google.golang.org/grpc@v1.65.0
1.79.3
1
envoyproxy/ratelimit:v1.4.071081616da3e
google.golang.org/grpc@v1.19.0
1.79.3
1
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
google.golang.org/grpc@v1.27.0
1.79.3
1
envoyproxy/ratelimit:4d2efd61ede09a75a84c
google.golang.org/grpc@v1.27.0
1.79.3
1
epamedp/edp-headlamp:0.25.093417e18bb1a
google.golang.org/grpc@v1.60.1
1.79.3
1
epamedp/edp-tekton:0.2.4924939850655
google.golang.org/grpc@v1.50.1
1.79.3
1
epamedp/tekton-custom-task:0.2.067d896676f45
google.golang.org/grpc@v1.70.0
1.79.3
1
erigontech/erigon:v2.61.288706754b627
google.golang.org/grpc@v1.63.2
1.79.3
1
ethereum/client-go:latest37575ec10fbc
google.golang.org/grpc@v1.79.1
1.79.3
1
ethereum/client-go:stableb8ab3451a117
google.golang.org/grpc@v1.79.1
1.79.3
1
ethpandaops/forky:debian-latestc937f4ba737c
google.golang.org/grpc@v1.72.1
1.79.3
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
google.golang.org/grpc@v1.74.2
1.79.3
1
ethpandaops/xatu-cbt-api:latestf7dec2e07091
google.golang.org/grpc@v1.76.0
1.79.3
1
evcc/evcc:0.300.8ddf2a25afce5
google.golang.org/grpc@v1.78.0
1.79.3
1
factly/mande-server:0.34.1384d384310ef
google.golang.org/grpc@v1.50.1
1.79.3
1
falcosecurity/falcosidekick:2.32.01976da721518
google.golang.org/grpc@v1.75.0
1.79.3
1
falcosecurity/falcosidekick:2.27.0828ee36cb13a
google.golang.org/grpc@v1.49.0
1.79.3
1
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
google.golang.org/grpc@v1.67.3
1.79.3
1
flanksource/apm-hub:v0.0.471dacc3195bf9
google.golang.org/grpc@v1.55.0
1.79.3
1
flanksource/batch-runner:v1.0.44689687a7cf95
google.golang.org/grpc@v1.71.1
1.79.3
1
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
google.golang.org/grpc@v1.40.0
1.79.3
1
fleetdm/fleet:v4.66.012e644b7f40e
google.golang.org/grpc@v1.67.1
1.79.3
1
flomesh/fsm-manager:0.2.1122f849c70b25
google.golang.org/grpc@v1.49.0
1.79.3
1
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
google.golang.org/grpc@v1.51.0
1.79.3
1
flomesh/osm-edge-controller:1.3.9add7a4da4622
google.golang.org/grpc@v1.51.0
1.79.3
1
flomesh/osm-edge-injector:1.3.947287e3ad324
google.golang.org/grpc@v1.51.0
1.79.3
1
fluxcd/helm-controller:v0.9.092b891e495d8
google.golang.org/grpc@v1.27.1
1.79.3
1
fluxcd/source-controller:v0.10.031a8c79a6803
google.golang.org/grpc@v1.27.1
1.79.3
1
fluxninja/aperture-operator:2.34.0356d7aa86632
google.golang.org/grpc@v1.60.1
1.79.3
1
fortio/fortio:latest_releasefc8221136fe2
google.golang.org/grpc@v1.72.1
1.79.3
1
fosrl/newt:1.10.4ccd2b0e9a049
google.golang.org/grpc@v1.79.1
1.79.3
1
foxcpp/maddy:0.7.16ab538e2f28b
google.golang.org/grpc@v1.60.1
1.79.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.