StackRadar

CVE-2026-33186

Critical

Advisory

Published 18 Mar 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,637
of 17,792 indexed, latest versions
Container images
1,988
deployed by those charts
Fix available
1 of 1
affected package

gRPC-Go has an authorization bypass via missing leading slash in :path

Carried by container images the latest versions of 1,637 of 17,792 indexed charts deploy, on 1,988 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+107 more1.79.31,988
OSV records
GHSA-p77j-4mvh-x3m3
Also known as
GO-2026-4762

Charts affected

1,637 by stars
ChartLatestAffected imagesRadar Score
IOMeshkubesphere-stable1.2.017 of 25See more

IOMesh kubesphere-stable 1.2.0

17 of the 25 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-driver:v2.8.01a151f602451
google.golang.org/grpc@v1.41.0
1.79.3
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
google.golang.org/grpc@v1.40.0
1.79.3
iomesh/csi-provisioner:v3.0.0f9508460b273
google.golang.org/grpc@v1.38.0
1.79.3
iomesh/csi-snapshotter:v6.2.2becc53e25b96
google.golang.org/grpc@v1.50.1
1.79.3
iomesh/deck:v0.2.0282d6c419ed3
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
google.golang.org/grpc@v1.60.0
1.79.3
iomesh/livenessprobe:v2.8.0560f01510f99
google.golang.org/grpc@v1.48.0
1.79.3
iomesh/localpv-manager:v0.2.0f13deacac3f4
google.golang.org/grpc@v1.50.0
1.79.3
iomesh/node-disk-manager:1.8.0-2292ad270082e
google.golang.org/grpc@v1.27.1
1.79.3
iomesh/operator:v1.2.0ba4dd6be7e59
google.golang.org/grpc@v1.41.0
1.79.3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/grpc@v1.54.0
1.79.3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
google.golang.org/grpc@v1.51.0
1.79.3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
google.golang.org/grpc@v1.51.0
1.79.3

Open the chart page →

46,692
pulsarkubesphere-stable2.7.132 of 3See more

pulsar kubesphere-stable 2.7.13

2 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
google.golang.org/grpc@v1.27.1
1.79.3
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
google.golang.org/grpc@v1.35.0
1.79.3

Open the chart page →

14,457
aws-fsx-csi-driverkubesphere-testVerified publisher0.1.01 of 4See more

aws-fsx-csi-driver kubesphere-test 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
amazon/aws-fsx-csi-driver:latestc9b14856fd22
google.golang.org/grpc@v1.23.1
1.79.3

Open the chart page →

1,595
cni-hostnickubesphere-testVerified publisher0.1.01 of 1See more

cni-hostnic kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
google.golang.org/grpc@v1.27.1
1.79.3

Open the chart page →

2,444
csi-neonsankubesphere-testVerified publisher1.3.06 of 6See more

csi-neonsan kubesphere-test 1.3.0

6 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-neonsan:v1.2.21fa83d45417f
google.golang.org/grpc@v1.26.0
1.79.3
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
google.golang.org/grpc@v1.34.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/grpc@v1.36.0
1.79.3

Open the chart page →

18,537
csi-qingcloudkubesphere-testVerified publisher1.4.06 of 6See more

csi-qingcloud kubesphere-test 1.4.0

6 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-qingcloud:v1.4.00766163dc046
google.golang.org/grpc@v1.26.0
1.79.3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
google.golang.org/grpc@v1.36.0
1.79.3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
google.golang.org/grpc@v1.34.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/grpc@v1.36.0
1.79.3

Open the chart page →

12,446
curvefs-csikubesphere-testVerified publisher0.1.01 of 3See more

curvefs-csi kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
google.golang.org/grpc@v1.10.0
1.79.3

Open the chart page →

2,831
minio-gatewaykubesphere-testVerified publisher0.1.01 of 1See more

minio-gateway kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
minio/minio:latest14cea493d9a3
google.golang.org/grpc@v1.71.0
1.79.3

Open the chart page →

1,084
online-boutiquekubesphere-testVerified publisher0.1.08 of 11See more

online-boutique kubesphere-test 0.1.0

8 of the 11 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
google.golang.org/grpc@v1.22.0
1.79.3
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
google.golang.org/grpc@v1.22.0
1.79.3
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
google.golang.org/grpc@v1.22.0
1.79.3
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
google.golang.org/grpc@v1.34.0
1.79.3
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
google.golang.org/grpc@v1.22.0
1.79.3

Open the chart page →

26,079
openelbkubesphere-testVerified publisher0.2.41 of 2See more

openelb kubesphere-test 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
google.golang.org/grpc@v1.26.0
1.79.3

Open the chart page →

4,336
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
google.golang.org/grpc@v1.26.0
1.79.3

Open the chart page →

2,791
kubestellar-consolekubestellar-consoleVerified publisher0.3.411 of 2See more

kubestellar-console kubestellar-console 0.3.41

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
alpine/k8s:1.32.47e1e7d5b7a96
google.golang.org/grpc@v1.68.0
1.79.3

Open the chart page →

4,458
kubestellar-uikubestellaruiVerified publisher0.1.11 of 4See more

kubestellar-ui kubestellarui 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
mavrick1/kubestellar-b:latest45ca0429a1d4
google.golang.org/grpc@v1.53.0
1.79.3

Open the chart page →

4,778
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.43 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

3 of the 9 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
google.golang.org/grpc@v1.67.1
1.79.3
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
google.golang.org/grpc@v1.65.0
1.79.3
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
google.golang.org/grpc@v1.73.0
1.79.3

Open the chart page →

20,435
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
google.golang.org/grpc@v1.49.0
1.79.3

Open the chart page →

3,477
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
google.golang.org/grpc@v1.69.0
1.79.3

Open the chart page →

6,969
dynatrace-operatorkvalitetsitVerified publisher1.3.01 of 1See more

dynatrace-operator kvalitetsit 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
google.golang.org/grpc@v1.65.0
1.79.3

Open the chart page →

1,320
krakendkvalitetsitVerified publisher0.0.31 of 1See more

krakend kvalitetsit 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
devopsfaith/krakend:latestf8bdaa8a1a43
google.golang.org/grpc@v1.66.0
1.79.3

Open the chart page →

1,249
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
google.golang.org/grpc@v1.23.0
1.79.3

Open the chart page →

16,561
metadockvalitetsitVerified publisher0.0.71 of 2See more

metadoc kvalitetsit 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-web:mainf57e7553f5bd
google.golang.org/grpc@v1.37.0
1.79.3

Open the chart page →

4,033
openidkvalitetsitVerified publisher1.7.21 of 2See more

openid kvalitetsit 1.7.2

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.14.368336da945bd
google.golang.org/grpc@v1.78.0
1.79.3

Open the chart page →

592
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

8,544
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

26,400
lagoon-docker-hostlagoon-chartsVerified publisher0.7.01 of 1See more

lagoon-docker-host lagoon-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
google.golang.org/grpc@v1.69.4
1.79.3

Open the chart page →

2,125
lambdapinglambdaping1.0.41 of 1See more

lambdaping lambdaping 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
udhos/lambdaping:1.0.46bd2cf2ac732
google.golang.org/grpc@v1.69.2
1.79.3

Open the chart page →

1,337
cachelavaOfficialVerified publisher1.1.11 of 1See more

cache lava 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
google.golang.org/grpc@v1.62.1
1.79.3

Open the chart page →

1,385
pinglbenicio-communityVerified publisher0.1.11 of 1See more

ping lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
google.golang.org/grpc@v1.77.0
1.79.3

Open the chart page →

600
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
google.golang.org/grpc@v1.72.2
1.79.3

Open the chart page →

33,613
prometheuslectures-k8sinfra15.8.51 of 6See more

prometheus lectures-k8sinfra 15.8.5

1 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
google.golang.org/grpc@v1.47.0
1.79.3

Open the chart page →

9,100
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
google.golang.org/grpc@v1.27.1
1.79.3

Open the chart page →

3,198
prometheusleechistest11.6.01 of 6See more

prometheus leechistest 11.6.0

1 of the 6 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
google.golang.org/grpc@v1.29.1
1.79.3

Open the chart page →

8,492
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
google.golang.org/grpc@v1.49.0
1.79.3

Open the chart page →

4,280
kltlifecycle-toolkitOfficialVerified publisher0.2.63 of 4See more

klt lifecycle-toolkit 0.2.6

3 of the 4 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/keptn/lifecycle-operator:v0.8.2487bfc37c4b4
google.golang.org/grpc@v1.57.0
1.79.3
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
google.golang.org/grpc@v1.52.3
1.79.3
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
google.golang.org/grpc@v1.57.0
1.79.3

Open the chart page →

4,680
lightsteplightstep-microsat2.0.211 of 1See more

lightstep lightstep-microsat 2.0.21

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
google.golang.org/grpc@v1.61.0
1.79.3

Open the chart page →

1,127
linkerd-preview-vizlinkerd-buoyantVerified publisher25.4.34 of 5See more

linkerd-preview-viz linkerd-buoyant 25.4.3

4 of the 5 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
google.golang.org/grpc@v1.71.1
1.79.3
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
google.golang.org/grpc@v1.66.0
1.79.3
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
google.golang.org/grpc@v1.71.1
1.79.3
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
google.golang.org/grpc@v1.71.1
1.79.3

Open the chart page →

3,454
linkerd-dashboardlinkerd-dashboardOfficial0.11.11 of 2See more

linkerd-dashboard linkerd-dashboard 0.11.1

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
google.golang.org/grpc@v1.71.0
1.79.3

Open the chart page →

1,050
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.44 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

4 of the 5 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
google.golang.org/grpc@v1.72.2
1.79.3
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
google.golang.org/grpc@v1.78.0
1.79.3
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
google.golang.org/grpc@v1.79.1
1.79.3
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.79.3

Open the chart page →

2,967
liqo-upgrade-operatorliqo-upgrade-operatorVerified publisher0.1.01 of 1See more

liqo-upgrade-operator liqo-upgrade-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
kazem26/liqo-upgrade-operator:v0.1268b7c6a59dd
google.golang.org/grpc@v1.72.1
1.79.3

Open the chart page →

375
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
google.golang.org/grpc@v1.60.1
1.79.3

Open the chart page →

10,814
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
google.golang.org/grpc@v1.42.0
1.79.3

Open the chart page →

2,136
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
google.golang.org/grpc@v1.72.2
1.79.3

Open the chart page →

1,560
llmarinerllmariner1.53.112 of 21See more

llmariner llmariner 1.53.1

12 of the 21 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
google.golang.org/grpc@v1.67.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
google.golang.org/grpc@v1.68.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
google.golang.org/grpc@v1.73.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/inference-manager-server:1.45.090b890f800ab
google.golang.org/grpc@v1.67.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/rbac-server:1.19.1df1adeb86679
google.golang.org/grpc@v1.67.0
1.79.3
public.ecr.aws/cloudnatix/llmariner/session-manager-server:1.9.0f24ecd37fbaa
google.golang.org/grpc@v1.67.1
1.79.3
public.ecr.aws/cloudnatix/llmariner/user-manager-server:1.27.1628a14449241
google.golang.org/grpc@v1.67.0
1.79.3

Open the chart page →

12,158
llm-dllm-dVerified publisher1.0.231 of 2See more

llm-d llm-d 1.0.23

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
google.golang.org/grpc@v1.71.1
1.79.3

Open the chart page →

2,540
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
google.golang.org/grpc@v1.63.2
1.79.3

Open the chart page →

2,162
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

4,911
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
google.golang.org/grpc@v1.56.2
1.79.3

Open the chart page →

2,108
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
google.golang.org/grpc@v1.65.0
1.79.3

Open the chart page →

2,027
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
google.golang.org/grpc@v1.27.0
1.79.3

Open the chart page →

7,519
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
google.golang.org/grpc@v1.62.1
1.79.3

Open the chart page →

7,544
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-33186.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
google.golang.org/grpc@v1.72.2
1.79.3

Open the chart page →

33,613

Container images carrying it

1,988 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
google.golang.org/grpc@v1.72.1
1.79.3
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
google.golang.org/grpc@v1.68.1
1.79.3
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
google.golang.org/grpc@v1.56.1
1.79.3
1
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
google.golang.org/grpc@v1.78.0
1.79.3
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
google.golang.org/grpc@v1.68.0
1.79.3
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
google.golang.org/grpc@v1.43.0
1.79.3
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
google.golang.org/grpc@v1.46.0
1.79.3
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
google.golang.org/grpc@v1.45.0
1.79.3
1
ghcr.io/edgelesssys/continuum/continuum-proxy24c76f294a80
google.golang.org/grpc@v1.69.0
1.79.3
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
google.golang.org/grpc@v1.36.0
1.79.3
1
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
google.golang.org/grpc@v1.67.3
1.79.3
1
ghcr.io/emqx/emqx-operator:2.3.23333ed546165
google.golang.org/grpc@v1.65.0
1.79.3
1
ghcr.io/erpc/erpc:0.0.49f5654f745d4c
google.golang.org/grpc@v1.67.1
1.79.3
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
google.golang.org/grpc@v1.59.0
1.79.3
1
ghcr.io/evilgn0me/ingressmonitorcontroller:v0.0.50bbfa4db14b9
google.golang.org/grpc@v1.67.1
1.79.3
1
ghcr.io/exalsius/exalsius-operator:0.12.0d24a579a3c75
google.golang.org/grpc@v1.75.1
1.79.3
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
google.golang.org/grpc@v1.27.0
1.79.3
1
ghcr.io/external-secrets/external-secrets:v2.1.0ec40c3d9c48f
google.golang.org/grpc@v1.76.0
1.79.3
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
google.golang.org/grpc@v1.54.0
1.79.3
1
ghcr.io/ferretdb/ferretdb:2.7.05706414241eb
google.golang.org/grpc@v1.75.0
1.79.3
1
ghcr.io/flohansen/dasher-server:latest7cde8c3fa2d1
google.golang.org/grpc@v1.64.0
1.79.3
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
google.golang.org/grpc@v1.67.1
1.79.3
1
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
google.golang.org/grpc@v1.65.0
1.79.3
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
google.golang.org/grpc@v1.68.1
1.79.3
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
google.golang.org/grpc@v1.46.2
1.79.3
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
google.golang.org/grpc@v1.51.0
1.79.3
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
google.golang.org/grpc@v1.74.2
1.79.3
1
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
google.golang.org/grpc@v1.70.0
1.79.3
1
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
google.golang.org/grpc@v1.68.0
1.79.3
1
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
google.golang.org/grpc@v1.71.0
1.79.3
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
google.golang.org/grpc@v1.56.3
1.79.3
1
ghcr.io/georgmangold/console:v1.8.158f4f180aa6e
google.golang.org/grpc@v1.70.0
1.79.3
1
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
google.golang.org/grpc@v1.74.2
1.79.3
1
ghcr.io/glauth/glauth:v2.5.209c782ca5984
google.golang.org/grpc@v1.59.0
1.79.3
1
ghcr.io/gochain/rpc-proxy/rpc-proxy:latestca01f5ab95f7
google.golang.org/grpc@v1.69.2
1.79.3
1
ghcr.io/gomenhashai/gomenhashai:v1.3.36f031172a5ec
google.golang.org/grpc@v1.72.2
1.79.3
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
google.golang.org/grpc@v1.73.0
1.79.3
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
google.golang.org/grpc@v1.75.1
1.79.3
1
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
google.golang.org/grpc@v1.73.0
1.79.3
1
ghcr.io/haedalwang/kubescout:0.1.107d51f838f0d
google.golang.org/grpc@v1.72.1
1.79.3
1
ghcr.io/haydercyber/secrets-bridge:0.2.04709f1bb3039
google.golang.org/grpc@v1.65.0
1.79.3
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
google.golang.org/grpc@v1.55.0
1.79.3
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
google.golang.org/grpc@v1.43.0
1.79.3
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
google.golang.org/grpc@v1.47.0
1.79.3
1
ghcr.io/helm/chartmuseum:v0.16.3c81f105c3682
google.golang.org/grpc@v1.65.0
1.79.3
1
ghcr.io/helmfile/helmfile:v1.7.4f20e612d5a98
google.golang.org/grpc@v1.68.1
1.79.3
1
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
google.golang.org/grpc@v1.36.0
1.79.3
1
ghcr.io/idebeijer/gameserver-operator:latest1b099cfe9e5e
google.golang.org/grpc@v1.72.2
1.79.3
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
google.golang.org/grpc@v1.67.1
1.79.3
1
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
google.golang.org/grpc@v1.75.1
1.79.3
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.