StackRadar

CVE-2026-84303

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,270
of 17,790 indexed, latest versions
Container images
2,748
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,270 of 17,790 indexed charts deploy, on 2,748 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+114 more1.83.12,745
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed3
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Trending
Rank 41 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,270 by stars
ChartLatestAffected imagesRadar Score
cert-manager-webhook-bluecatcontainerooVerified publisher1.0.21 of 1See more

cert-manager-webhook-bluecat containeroo 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cert-manager-webhook-bluecat:latest96f82d5840d4
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

434
kube-ephemeral-container-exportercontainerooVerified publisher0.2.31 of 1See more

kube-ephemeral-container-exporter containeroo 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/containeroo/kube-ephemeral-container-exporter:v0.0.14b238f3c58d83
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

298
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.27.0828ee36cb13a
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

9,146
coordimap-agentcoordimap-agentVerified publisher0.4.31 of 1See more

coordimap-agent coordimap-agent 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
coordimap/coordimap-agent:latest7748fd0fae9f
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

618
cortezacorteza1.1.01 of 3See more

corteza corteza 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
google.golang.org/grpc@v1.61.1
1.83.1

Open the chart page →

8,251
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
google.golang.org/grpc@v1.61.1
1.83.1

Open the chart page →

4,682
cosanetcosanet1.0.01 of 1See more

cosanet cosanet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
google.golang.org/grpc@v1.75.0
1.83.1

Open the chart page →

2,188
ociscosmicrocks0.7.01 of 2See more

ocis cosmicrocks 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
owncloud/ocis:7.1.388e7c854517d
google.golang.org/grpc@v1.68.0
1.83.1

Open the chart page →

1,925
cosmo-traefikcosmoVerified publisher0.9.11 of 2See more

cosmo-traefik cosmo 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/traefik:v2.10.11489caffaedb
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

3,672
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/docker:dind5efed980cba3
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

14,587
cospacecospace0.0.341 of 3See more

cospace cospace 0.0.34

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/twigex/cospace:lateste5ecfd607e42
google.golang.org/grpc@v1.62.0
1.83.1

Open the chart page →

2,202
grafana-mcpcowboysysopVerified publisher2.0.01 of 1See more

grafana-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
mcp/grafana:latest9362bcf6aa0e
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

1,193
katibcowboysysopVerified publisher2.4.23 of 4See more

katib cowboysysop 2.4.2

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
google.golang.org/grpc@v1.32.0
1.83.1
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
google.golang.org/grpc@v1.32.0
1.83.1
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
google.golang.org/grpc@v1.32.0
1.83.1

Open the chart page →

6,542
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
google.golang.org/grpc@v1.31.1
1.83.1

Open the chart page →

3,830
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

1,814
chalkularcrashoverride-helm-chartsVerified publisher0.0.81 of 1See more

chalkular crashoverride-helm-charts 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/chalkular-controller:v0.0.8d31986456626
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

47
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,625
electric-mailcryptexlabsVerified publisher0.0.11 of 5See more

electric-mail cryptexlabs 0.0.1

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

5,973
purple-piecryptexlabsVerified publisher0.0.11 of 4See more

purple-pie cryptexlabs 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

5,973
agent-sandboxcsghubVerified publisher0.5.41 of 1See more

agent-sandbox csghub 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.4be477ba317d8
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

87
csghubcsghubVerified publisher2.4.317 of 34See more

csghub csghub 2.4.3

17 of the 34 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.0e08231f16c00
google.golang.org/grpc@v1.79.3
1.83.1
envoyproxy/gateway:v1.7.5156b7d32c73b
google.golang.org/grpc@v1.82.0
1.83.1
grafana/loki:3.4.258a6c186ce78
google.golang.org/grpc@v1.70.0
1.83.1
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
google.golang.org/grpc@v1.71.0
1.83.1
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
google.golang.org/grpc@v1.80.0
1.83.1
opencsghq/csghub-xnet:v2.4.0-ee04121fd19ef9
google.golang.org/grpc@v1.71.0
1.83.1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
google.golang.org/grpc@v1.67.1
1.83.1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
google.golang.org/grpc@v1.65.0
1.83.1
opencsghq/kube-state-metrics:v2.19.15ea147562ec8
google.golang.org/grpc@v1.79.3
1.83.1
opencsghq/lws:v0.6.1de15437db41b
google.golang.org/grpc@v1.65.0
1.83.1
opencsghq/prometheus:v3.13.00aac0d04749e
google.golang.org/grpc@v1.81.1
1.83.1
temporalio/auto-setup:1.29.7f14912b699cf
google.golang.org/grpc@v1.79.3
1.83.1
gcr.io/knative-releases/knative.dev/operator/cmd/operator:v1.22.1ea30f1ce8dc4
google.golang.org/grpc@v1.80.0
1.83.1
gcr.io/knative-releases/knative.dev/operator/cmd/webhook:v1.22.195d1a4fc8cd0
google.golang.org/grpc@v1.80.0
1.83.1
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
google.golang.org/grpc@v1.72.2
1.83.1
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
google.golang.org/grpc@v1.72.2
1.83.1
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.4be477ba317d8
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

59,131
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
google.golang.org/grpc@v1.79.3
1.83.1
envoyproxy/gateway:v1.7.5156b7d32c73b
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

11,402
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.7.5156b7d32c73b
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

6,532
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

14,206
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

13,937
csi-driver-ipfscsi-driver-ipfs0.2.06 of 6See more

csi-driver-ipfs csi-driver-ipfs 0.2.0

6 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
google.golang.org/grpc@v1.75.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
google.golang.org/grpc@v1.78.0
1.83.1

Open the chart page →

3,630
ipfs-clustercsi-driver-ipfs0.2.02 of 2See more

ipfs-cluster csi-driver-ipfs 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:v1.1.6a83266c524f1
google.golang.org/grpc@v1.81.0
1.83.1
ipfs/kubo:v0.41.00661819c2e09
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,475
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

1,232
cw-container-insightcwci0.7.01 of 1See more

cw-container-insight cwci 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:latest-arm649dea6643715a
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

274
cloudflaredcyberjakeVerified publisher0.3.201 of 1See more

cloudflared cyberjake 0.3.20

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.6.16d91c121b803
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

601
irods-csi-drivercyverse0.12.04 of 4See more

irods-csi-driver cyverse 0.12.0

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cyverse/irods-csi-driver:v0.12.0aa69d105b292
google.golang.org/grpc@v1.81.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
google.golang.org/grpc@v1.59.0
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/grpc@v1.40.0
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
google.golang.org/grpc@v1.58.0
1.83.1

Open the chart page →

5,257
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
google.golang.org/grpc@v1.65.0
1.83.1
registry.k8s.io/kube-scheduler:v1.28.1146cf7475c8da
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

16,632
miniod4nVerified publisher5.2.12 of 2See more

minio d4n 5.2.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-04-29T09-56-05Zc574fac67f60
google.golang.org/grpc@v1.63.2
1.83.1
quay.io/minio/minio:RELEASE.2024-06-04T19-20-08Zc6b68f158628
google.golang.org/grpc@v1.63.2
1.83.1

Open the chart page →

2,645
cloudflareddamounVerified publisher3.3.01 of 1See more

cloudflared damoun 3.3.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.5.05d5f70a59d5e
google.golang.org/grpc@v1.63.0
1.83.1

Open the chart page →

1,306
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

3,238
dapr-agentsdapr-agents-devVerified publisher0.1.515 of 31See more

dapr-agents dapr-agents-dev 0.1.5

15 of the 31 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:12.3.39e1e77ade304
google.golang.org/grpc@v1.78.0
1.83.1
grafana/loki:3.6.5847c287ada0e
google.golang.org/grpc@v1.75.1
1.83.1
grafana/loki-canary:3.6.5fbb984bab741
google.golang.org/grpc@v1.75.1
1.83.1
grafana/tempo:2.9.065a578975943
google.golang.org/grpc@v1.75.0
1.83.1
mcp/grafana:latest9362bcf6aa0e
google.golang.org/grpc@v1.80.0
1.83.1
otel/opentelemetry-collector-contrib:0.145.0a7343f018690
google.golang.org/grpc@v1.78.0
1.83.1
ghcr.io/dapr/injector:1.17.0-rc.37a2fd888ed5f
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/dapr/operator:1.17.0-rc.3d5cc61cbe735
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/dapr/placement:1.17.0-rc.3a237b43cd5c6
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/dapr/scheduler:1.17.0-rc.36c62e01e736b
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/dapr/sentry:1.17.0-rc.3bf79b03591e0
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/kagent-dev/kagent/tools:0.0.13c8882543f693
google.golang.org/grpc@v1.76.0
1.83.1
ghcr.io/kagent-dev/kmcp/controller:0.2.283276357d448
google.golang.org/grpc@v1.65.0
1.83.1
public.ecr.aws/diagrid-dev/diagrid-dashboard:latestf1348a65664a
google.golang.org/grpc@v1.80.0
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
google.golang.org/grpc@v1.75.1
1.83.1

Open the chart page →

22,223
dns-mesh-controllerdashdns2.0.81 of 2See more

dns-mesh-controller dashdns 2.0.8

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

1,096
dasherdasher0.1.11 of 1See more

dasher dasher 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/flohansen/dasher-server:latest7cde8c3fa2d1
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

1,089
dask-gatewaydask2026.3.01 of 2See more

dask-gateway dask 2026.3.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/traefik:3.3.5104204dadedf
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

1,994
cloudwatch-agent-prometheusdasmeta0.2.21 of 1See more

cloudwatch-agent-prometheus dasmeta 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
google.golang.org/grpc@v1.28.0
1.83.1

Open the chart page →

2,977
spqr-routerdasmeta0.1.11 of 1See more

spqr-router dasmeta 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
pgsharding/spqr-router:nightly-2.8.3-1839-f66048d84734940216d3
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

680
adot-exporter-for-eks-on-ec2dasmeta-adot0.15.51 of 1See more

adot-exporter-for-eks-on-ec2 dasmeta-adot 0.15.5

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

1,926
monitoring-stackdata354-helmVerified publisher1.4.23 of 4See more

monitoring-stack data354-helm 1.4.2

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
grafana/loki:latestd70e4659623f
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

3,189
datadog-csi-driverdatadogVerified publisher0.17.02 of 2See more

datadog-csi-driver datadog 0.17.0

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gcr.io/datadoghq/csi-driver:1.4.086c713de81d9
google.golang.org/grpc@v1.83.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

2,041
agent-helmdatasaker0.1.85 of 6See more

agent-helm datasaker 0.1.8

5 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
datasaker/dsk-container-agent:latest08b52999f67b
google.golang.org/grpc@v1.57.0
1.83.1
datasaker/dsk-k8s-agent:latest2542ee73be51
google.golang.org/grpc@v1.50.1
1.83.1
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
google.golang.org/grpc@v1.58.3
1.83.1
datasaker/dsk-node-agent:latest1b95913b6729
google.golang.org/grpc@v1.58.3
1.83.1
datasaker/dsk-process-agent:latest2f38720a637d
google.golang.org/grpc@v1.58.3
1.83.1

Open the chart page →

7,571
ambassador-agentdatawire1.0.221 of 1See more

ambassador-agent datawire 1.0.22

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ambassador/ambassador-agent:1.0.227a1ea0d934fb
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

958
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
google.golang.org/grpc@v1.24.0
1.83.1

Open the chart page →

7,486
eg-edge-stackdatawire0.0.13 of 7See more

eg-edge-stack datawire 0.0.1

3 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
google.golang.org/grpc@v1.56.2
1.83.1
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
google.golang.org/grpc@v1.56.2
1.83.1
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/grpc@v1.56.2
1.83.1

Open the chart page →

15,781
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
defactops/defactops-ui:1.0.16825cdf9ba706
google.golang.org/grpc@v1.62.1
1.83.1

Open the chart page →

4,353
csi-driver-smbdeimosfr-charts1.20.35 of 5See more

csi-driver-smb deimosfr-charts 1.20.3

5 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
google.golang.org/grpc@v1.79.3
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

2,952

Container images carrying it

2,748 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/skywalking-oap-server:8.1.0-es7641237e0299b
google.golang.org/grpc@v1.24.0
1.83.1
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
google.golang.org/grpc@v1.38.0
1.83.1
1
apache/skywalking-ui:8.1.067d50e4deff4
google.golang.org/grpc@v1.24.0
1.83.1
1
apache/yunikorn:scheduler-1.9.096832082e9cf
google.golang.org/grpc@v1.79.3
1.83.1
1
apache/yunikorn:admission-1.9.0fe8f5ec91f6c
google.golang.org/grpc@v1.79.3
1.83.1
1
apecloud/gemini-scheduler:0.1.15832d1a9097a
google.golang.org/grpc@v1.63.2
1.83.1
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
google.golang.org/grpc@v1.68.1
1.83.1
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
google.golang.org/grpc@v1.47.0
1.83.1
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
google.golang.org/grpc@v1.53.0
1.83.1
1
appwrite/appwrite:1.9.01aaa70127114
google.golang.org/grpc@v1.74.2
1.83.1
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
google.golang.org/grpc@v1.63.2
1.83.1
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
google.golang.org/grpc@v1.35.0
1.83.1
1
aquasec/tracee:0.24.1cfbbfee972e6
google.golang.org/grpc@v1.72.0
1.83.1
1
aquasec/trivy:0.43.1944a04445179
google.golang.org/grpc@v1.55.0
1.83.1
1
aquasec/trivy:0.32.0973d0df16189
google.golang.org/grpc@v1.49.0
1.83.1
1
aquasec/trivy:0.69.3bcc376de8d77
google.golang.org/grpc@v1.78.0
1.83.1
1
aristidetm/basic-notebook:3.6.5469dbc951224
google.golang.org/grpc@v1.65.0
1.83.1
1
artifacthub/hub:v1.19.0111918d8c399
google.golang.org/grpc@v1.64.0
1.83.1
1
artifacthub/hub:v1.23.07d3a91c539dc
google.golang.org/grpc@v1.82.0
1.83.1
1
artifacthub/scanner:v1.23.02d8365601f0e
google.golang.org/grpc@v1.78.0
1.83.1
1
artifacthub/scanner:v1.19.0323d026e78c3
google.golang.org/grpc@v1.64.0
1.83.1
1
artifacthub/tracker:v1.23.05368d21a6e5c
google.golang.org/grpc@v1.75.1
1.83.1
1
artifacthub/tracker:v1.19.06596c8c4d955
google.golang.org/grpc@v1.61.1
1.83.1
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
google.golang.org/grpc@v1.29.1
1.83.1
1
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
google.golang.org/grpc@v1.33.1
1.83.1
1
assistiot/distributed_broker:1.0.033e02dad168f
google.golang.org/grpc@v1.33.1
1.83.1
1
assistiot/dlt_based_fl:1.1.04bc3d92788ed
google.golang.org/grpc@v1.33.1
1.83.1
1
assistiot/logging_auditing:1.0.0790dbb198e86
google.golang.org/grpc@v1.29.1
1.83.1
1
astarte/astarte-kubernetes-operator:26.5.1e3ff1b3c0c98
google.golang.org/grpc@v1.65.0
1.83.1
1
authzed/spicedb:latestdb0d1a16e6a4
google.golang.org/grpc@v1.83.0
1.83.1
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
google.golang.org/grpc@v1.64.0
1.83.1
1
aveshasystems/spiffe-csi-driver:0.2.753fc6d009e04
google.golang.org/grpc@v1.63.2
1.83.1
1
baserow/baserow:1.30.1df0c42eb67e8
google.golang.org/grpc@v1.59.0
1.83.1
1
bedag/goblackhole:0.2.0447a88598f4c
google.golang.org/grpc@v1.39.1
1.83.1
1
beopenit/door-agent:v3.0.5d24c323fe7c3
google.golang.org/grpc@v1.65.1
1.83.1
1
beopenit/door-helm:v3.0.1b4d9f9bee224
google.golang.org/grpc@v1.53.0
1.83.1
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
google.golang.org/grpc@v1.45.0
1.83.1
1
bicarus/wg-access-server:v0.8.206cab48e9334
google.golang.org/grpc@v1.50.1
1.83.1
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
google.golang.org/grpc@v1.63.2
1.83.1
1
binwiederhier/ntfy:v2.6.283e2e43d9956
google.golang.org/grpc@v1.56.1
1.83.1
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
google.golang.org/grpc@v1.65.0
1.83.1
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
google.golang.org/grpc@v1.66.0
1.83.1
1
bitnamilegacy/kube-state-metrics:204a3044b384b
google.golang.org/grpc@v1.68.1
1.83.1
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
google.golang.org/grpc@v1.60.1
1.83.1
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
google.golang.org/grpc@v1.50.1
1.83.1
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
google.golang.org/grpc@v1.65.0
1.83.1
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
google.golang.org/grpc@v1.60.1
1.83.1
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
google.golang.org/grpc@v1.71.0
1.83.1
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
google.golang.org/grpc@v1.71.0
1.83.1
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
google.golang.org/grpc@v1.65.0
1.83.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.