StackRadar

CVE-2026-33186

Critical

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,641
of 17,790 indexed, latest versions
Container images
1,992
deployed by those charts
Fix available
1 of 1
affected package

gRPC-Go has an authorization bypass via missing leading slash in :path

Carried by container images the latest versions of 1,641 of 17,790 indexed charts deploy, on 1,992 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+107 more1.79.31,992
OSV records
GHSA-p77j-4mvh-x3m3
Also known as
GO-2026-4762

Charts affected

1,641 by stars
ChartLatestAffected imagesRadar Score
edgemeshkubesphere-stable0.1.01 of 2See more

edgemesh kubesphere-stable 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubeedge/edgemesh-agent:latest460c6061b608
google.golang.org/grpc@v1.42.0
1.79.3

Open the chart page →

4,108
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
inaccel/daemon:latest093e1ea90ab8
google.golang.org/grpc@v1.61.0
1.79.3

Open the chart page →

5,770
iomeshkubesphere-stable1.1.017 of 25See more

iomesh kubesphere-stable 1.1.0

17 of the 25 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-driver:v2.7.25d3f9bf9240b
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
google.golang.org/grpc@v1.40.0
1.79.3
iomesh/csi-provisioner:v3.0.0f9508460b273
google.golang.org/grpc@v1.38.0
1.79.3
iomesh/csi-snapshotter:v6.2.2becc53e25b96
google.golang.org/grpc@v1.50.1
1.79.3
iomesh/deck:v0.1.0a31e26b6ae22
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/livenessprobe:v2.8.0560f01510f99
google.golang.org/grpc@v1.48.0
1.79.3
iomesh/localpv-manager:v0.2.0f13deacac3f4
google.golang.org/grpc@v1.50.0
1.79.3
iomesh/node-disk-manager:1.8.0002c4b92fd34
google.golang.org/grpc@v1.27.1
1.79.3
iomesh/operator:v1.1.060081c9b2f52
google.golang.org/grpc@v1.41.0
1.79.3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
google.golang.org/grpc@v1.51.0
1.79.3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
google.golang.org/grpc@v1.51.0
1.79.3

Open the chart page →

48,954
IOMeshkubesphere-stable1.2.017 of 25See more

IOMesh kubesphere-stable 1.2.0

17 of the 25 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-driver:v2.8.01a151f602451
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
google.golang.org/grpc@v1.40.0
1.79.3
iomesh/csi-provisioner:v3.0.0f9508460b273
google.golang.org/grpc@v1.38.0
1.79.3
iomesh/csi-snapshotter:v6.2.2becc53e25b96
google.golang.org/grpc@v1.50.1
1.79.3
iomesh/deck:v0.2.0282d6c419ed3
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/livenessprobe:v2.8.0560f01510f99
google.golang.org/grpc@v1.48.0
1.79.3
iomesh/localpv-manager:v0.2.0f13deacac3f4
google.golang.org/grpc@v1.50.0
1.79.3
iomesh/node-disk-manager:1.8.0-2292ad270082e
google.golang.org/grpc@v1.27.1
1.79.3
iomesh/operator:v1.2.0ba4dd6be7e59
google.golang.org/grpc@v1.41.0
1.79.3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
google.golang.org/grpc@v1.51.0
1.79.3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
google.golang.org/grpc@v1.51.0
1.79.3

Open the chart page →

46,639
pulsarkubesphere-stable2.7.132 of 3See more

pulsar kubesphere-stable 2.7.13

2 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
google.golang.org/grpc@v1.27.1
1.79.3
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
google.golang.org/grpc@v1.35.0
1.79.3

Open the chart page →

14,401
aws-fsx-csi-driverkubesphere-testVerified publisher0.1.01 of 4See more

aws-fsx-csi-driver kubesphere-test 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
amazon/aws-fsx-csi-driver:latestc9b14856fd22
google.golang.org/grpc@v1.23.1
1.79.3

Open the chart page →

1,594
cni-hostnickubesphere-testVerified publisher0.1.01 of 1See more

cni-hostnic kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
google.golang.org/grpc@v1.27.1
1.79.3

Open the chart page →

2,443
csi-neonsankubesphere-testVerified publisher1.3.06 of 6See more

csi-neonsan kubesphere-test 1.3.0

6 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-neonsan:v1.2.21fa83d45417f
google.golang.org/grpc@v1.26.0
1.79.3
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
google.golang.org/grpc@v1.34.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/grpc@v1.36.0
1.79.3

Open the chart page →

18,526
csi-qingcloudkubesphere-testVerified publisher1.4.06 of 6See more

csi-qingcloud kubesphere-test 1.4.0

6 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-qingcloud:v1.4.00766163dc046
google.golang.org/grpc@v1.26.0
1.79.3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
google.golang.org/grpc@v1.34.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/grpc@v1.36.0
1.79.3

Open the chart page →

12,444
curvefs-csikubesphere-testVerified publisher0.1.01 of 3See more

curvefs-csi kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
google.golang.org/grpc@v1.10.0
1.79.3

Open the chart page →

2,831
minio-gatewaykubesphere-testVerified publisher0.1.01 of 1See more

minio-gateway kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
google.golang.org/grpc@v1.71.0
1.79.3

Open the chart page →

1,084
online-boutiquekubesphere-testVerified publisher0.1.08 of 11See more

online-boutique kubesphere-test 0.1.0

8 of the 11 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
google.golang.org/grpc@v1.22.0
1.79.3
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
google.golang.org/grpc@v1.22.0
1.79.3
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
google.golang.org/grpc@v1.22.0
1.79.3
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
google.golang.org/grpc@v1.22.0
1.79.3

Open the chart page →

26,075
openelbkubesphere-testVerified publisher0.2.41 of 2See more

openelb kubesphere-test 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
google.golang.org/grpc@v1.26.0
1.79.3

Open the chart page →

4,336
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
google.golang.org/grpc@v1.26.0
1.79.3

Open the chart page →

2,791
kubestellar-consolekubestellar-consoleVerified publisher0.3.411 of 2See more

kubestellar-console kubestellar-console 0.3.41

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
alpine/k8s:1.32.47e1e7d5b7a96
google.golang.org/grpc@v1.68.0
1.79.3

Open the chart page →

4,456
kubestellar-uikubestellaruiVerified publisher0.1.11 of 4See more

kubestellar-ui kubestellarui 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
mavrick1/kubestellar-b:latest45ca0429a1d4
google.golang.org/grpc@v1.53.0
1.79.3

Open the chart page →

4,773
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.43 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

3 of the 9 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
google.golang.org/grpc@v1.67.1
1.79.3
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
google.golang.org/grpc@v1.65.0
1.79.3
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
google.golang.org/grpc@v1.73.0
1.79.3

Open the chart page →

20,386
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
google.golang.org/grpc@v1.49.0
1.79.3

Open the chart page →

3,469
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
google.golang.org/grpc@v1.69.0
1.79.3

Open the chart page →

6,913
dynatrace-operatorkvalitetsitVerified publisher1.3.01 of 1See more

dynatrace-operator kvalitetsit 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
google.golang.org/grpc@v1.65.0
1.79.3

Open the chart page →

1,320
krakendkvalitetsitVerified publisher0.0.31 of 1See more

krakend kvalitetsit 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
devopsfaith/krakend:latestf8bdaa8a1a43
google.golang.org/grpc@v1.66.0
1.79.3

Open the chart page →

1,249
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
google.golang.org/grpc@v1.23.0
1.79.3

Open the chart page →

16,539
metadockvalitetsitVerified publisher0.0.71 of 2See more

metadoc kvalitetsit 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-web:mainf57e7553f5bd
google.golang.org/grpc@v1.37.0
1.79.3

Open the chart page →

4,033
openidkvalitetsitVerified publisher1.7.21 of 2See more

openid kvalitetsit 1.7.2

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.14.368336da945bd
google.golang.org/grpc@v1.78.0
1.79.3

Open the chart page →

592
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

8,543
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

26,377
lagoon-docker-hostlagoon-chartsVerified publisher0.7.01 of 1See more

lagoon-docker-host lagoon-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
google.golang.org/grpc@v1.69.4
1.79.3

Open the chart page →

2,122
lambdapinglambdaping1.0.41 of 1See more

lambdaping lambdaping 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
udhos/lambdaping:1.0.46bd2cf2ac732
google.golang.org/grpc@v1.69.2
1.79.3

Open the chart page →

1,337
cachelavaOfficialVerified publisher1.1.11 of 1See more

cache lava 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
google.golang.org/grpc@v1.62.1
1.79.3

Open the chart page →

1,385
pinglbenicio-communityVerified publisher0.1.11 of 1See more

ping lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
google.golang.org/grpc@v1.77.0
1.79.3

Open the chart page →

600
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
google.golang.org/grpc@v1.72.2
1.79.3

Open the chart page →

33,540
prometheuslectures-k8sinfra15.8.51 of 6See more

prometheus lectures-k8sinfra 15.8.5

1 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
google.golang.org/grpc@v1.47.0
1.79.3

Open the chart page →

9,100
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
google.golang.org/grpc@v1.27.1
1.79.3

Open the chart page →

3,198
prometheusleechistest11.6.01 of 6See more

prometheus leechistest 11.6.0

1 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
google.golang.org/grpc@v1.29.1
1.79.3

Open the chart page →

8,491
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
google.golang.org/grpc@v1.49.0
1.79.3

Open the chart page →

4,280
minioleprechaun-charts0.1.61 of 1See more

minio leprechaun-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-01-20T14-49-07Z-cpuv114b7076ca85a
google.golang.org/grpc@v1.69.2
1.79.3

Open the chart page →

1,319
kltlifecycle-toolkitOfficialVerified publisher0.2.63 of 4See more

klt lifecycle-toolkit 0.2.6

3 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/keptn/lifecycle-operator:v0.8.2487bfc37c4b4
google.golang.org/grpc@v1.57.0
1.79.3
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
google.golang.org/grpc@v1.52.3
1.79.3
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
google.golang.org/grpc@v1.57.0
1.79.3

Open the chart page →

4,680
lightsteplightstep-microsat2.0.211 of 1See more

lightstep lightstep-microsat 2.0.21

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
google.golang.org/grpc@v1.61.0
1.79.3

Open the chart page →

1,127
linkerd-preview-vizlinkerd-buoyantVerified publisher25.4.34 of 5See more

linkerd-preview-viz linkerd-buoyant 25.4.3

4 of the 5 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
google.golang.org/grpc@v1.71.1
1.79.3
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
google.golang.org/grpc@v1.66.0
1.79.3
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
google.golang.org/grpc@v1.71.1
1.79.3
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
google.golang.org/grpc@v1.71.1
1.79.3

Open the chart page →

3,454
linkerd-dashboardlinkerd-dashboardOfficial0.11.11 of 2See more

linkerd-dashboard linkerd-dashboard 0.11.1

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
google.golang.org/grpc@v1.71.0
1.79.3

Open the chart page →

1,050
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.44 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

4 of the 5 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
google.golang.org/grpc@v1.72.2
1.79.3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
google.golang.org/grpc@v1.78.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
google.golang.org/grpc@v1.79.1
1.79.3
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.79.3

Open the chart page →

2,967
liqo-upgrade-operatorliqo-upgrade-operatorVerified publisher0.1.01 of 1See more

liqo-upgrade-operator liqo-upgrade-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kazem26/liqo-upgrade-operator:v0.1268b7c6a59dd
google.golang.org/grpc@v1.72.1
1.79.3

Open the chart page →

375
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
google.golang.org/grpc@v1.60.1
1.79.3

Open the chart page →

10,780
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
google.golang.org/grpc@v1.42.0
1.79.3

Open the chart page →

2,135
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
google.golang.org/grpc@v1.72.2
1.79.3

Open the chart page →

1,560
llmarinerllmariner1.53.112 of 21See more

llmariner llmariner 1.53.1

12 of the 21 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
google.golang.org/grpc@v1.67.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
google.golang.org/grpc@v1.68.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
google.golang.org/grpc@v1.73.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/inference-manager-server:1.45.090b890f800ab
google.golang.org/grpc@v1.67.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
google.golang.org/grpc@v1.67.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/user-manager-server:1.27.1628a14449241
google.golang.org/grpc@v1.67.0
1.79.3

Open the chart page →

12,150
llm-dllm-dVerified publisher1.0.231 of 2See more

llm-d llm-d 1.0.23

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
google.golang.org/grpc@v1.71.1
1.79.3

Open the chart page →

2,539
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
google.golang.org/grpc@v1.63.2
1.79.3

Open the chart page →

2,162
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

4,911
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
google.golang.org/grpc@v1.56.2
1.79.3

Open the chart page →

2,108

Container images carrying it

1,992 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
foxcpp/maddy:0.7.16ab538e2f28b
google.golang.org/grpc@v1.60.1
1.79.3
1
foxcpp/maddy:0.9.2a4b839985b9b
google.golang.org/grpc@v1.70.0
1.79.3
1
foxcpp/maddy:0.8.2eeb5813fc4d1
google.golang.org/grpc@v1.70.0
1.79.3
1
galaxy/cloudman-server:lateste5c265fe9fcd
google.golang.org/grpc@v1.43.0
1.79.3
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
google.golang.org/grpc@v1.67.0
1.79.3
1
gboxproxy/gbox:v1.0.63a9f4a711d5c
google.golang.org/grpc@v1.44.0
1.79.3
1
gdxbsv/traktor:0.0.17675693335054
google.golang.org/grpc@v1.68.1
1.79.3
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
google.golang.org/grpc@v1.62.0
1.79.3
1
gitea/gitea:1.22.376f516a1a8c2
google.golang.org/grpc@v1.62.1
1.79.3
1
gitea/gitea:1.21.6ac73e0da341f
google.golang.org/grpc@v1.58.3
1.79.3
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
google.golang.org/grpc@v1.34.0
1.79.3
1
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
google.golang.org/grpc@v1.21.1
1.79.3
1
goalert/goalert:v0.32.008d57388b0cb
google.golang.org/grpc@v1.61.0
1.79.3
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
google.golang.org/grpc@v1.69.4
1.79.3
1
goccx/go-file-server:latestf4b3ebea0303
google.golang.org/grpc@v1.65.0
1.79.3
1
gocrane/craned:v0.5.1a1400909118c
google.golang.org/grpc@v1.43.0
1.79.3
1
gocrane/crane-scheduler:0.0.239ba6d11b2079
google.golang.org/grpc@v1.40.0
1.79.3
1
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
google.golang.org/grpc@v1.43.0
1.79.3
1
goharbor/harbor-acceld:0.2.13451103a6c8d8
google.golang.org/grpc@v1.59.0
1.79.3
1
goharbor/harbor-core:v2.9.06412d679fdc3
google.golang.org/grpc@v1.53.0
1.79.3
1
goharbor/harbor-core:v2.5.386bf3031f4a7
google.golang.org/grpc@v1.41.0
1.79.3
1
goharbor/harbor-core:v2.14.3a30e5a8be3d9
google.golang.org/grpc@v1.69.4
1.79.3
1
goharbor/harbor-core:v2.11.1c017dd84ee96
google.golang.org/grpc@v1.63.2
1.79.3
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
google.golang.org/grpc@v1.53.0
1.79.3
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
google.golang.org/grpc@v1.41.0
1.79.3
1
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
google.golang.org/grpc@v1.69.4
1.79.3
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
google.golang.org/grpc@v1.41.0
1.79.3
1
goharbor/harbor-registryctl:v2.9.0cce272836449
google.golang.org/grpc@v1.53.0
1.79.3
1
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
google.golang.org/grpc@v1.69.4
1.79.3
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
google.golang.org/grpc@v1.27.1
1.79.3
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
google.golang.org/grpc@v1.27.1
1.79.3
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
google.golang.org/grpc@v1.78.0
1.79.3
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
google.golang.org/grpc@v1.47.0
1.79.3
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
google.golang.org/grpc@v1.55.0
1.79.3
1
gomods/athens:v0.8.1d714c7ff0231
google.golang.org/grpc@v1.20.1
1.79.3
1
gomods/athens:v0.11.0efb811df7844
google.golang.org/grpc@v1.26.0
1.79.3
1
grafana/agent:v0.44.23364714a2f64
google.golang.org/grpc@v1.66.0
1.79.3
1
grafana/agent:v0.20.0825c09373d27
google.golang.org/grpc@v1.41.0
1.79.3
1
grafana/agent:v0.40.3f6cbec9409be
google.golang.org/grpc@v1.61.0
1.79.3
1
grafana/agent-operator:v0.34.1045c9125634c
google.golang.org/grpc@v1.45.0
1.79.3
1
grafana/alloy:v1.5.101a63f4e032c
google.golang.org/grpc@v1.67.1
1.79.3
1
grafana/alloy:v1.4.306bdcbb51fc2
google.golang.org/grpc@v1.65.0
1.79.3
1
grafana/alloy:v1.11.38c7256f412fe
google.golang.org/grpc@v1.75.0
1.79.3
1
grafana/alloy:v1.1.1c3dac4e26471
google.golang.org/grpc@v1.63.2
1.79.3
1
grafana/alloy:v1.14.0f50931848bd8
google.golang.org/grpc@v1.78.0
1.79.3
1
grafana/beyla:1.3.336d07f8d276e
google.golang.org/grpc@v1.61.0
1.79.3
1
grafana/beyla-k8s-cache:253b2f561cb1b
google.golang.org/grpc@v1.77.0
1.79.3
1
grafana/grafana:6.6.0052147d7e0ec
google.golang.org/grpc@v1.23.1
1.79.3
1
grafana/grafana:10.1.50679e877ba20
google.golang.org/grpc@v1.45.0
1.79.3
1
grafana/grafana:7.5.609bb407e26ab
google.golang.org/grpc@v1.36.0
1.79.3
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.