StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,312
of 17,828 indexed, latest versions
Container images
2,773
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,312 of 17,828 indexed charts deploy, on 2,773 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,769
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,312 by stars
ChartLatestAffected imagesRadar Score
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

1,061
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

13,934
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

402
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

9,769
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,530
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,003
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,077

Container images carrying it

2,773 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
beopenit/door-agent:v3.0.5d24c323fe7c3
google.golang.org/grpc@v1.65.1
1.83.1
1
beopenit/door-helm:v3.0.1b4d9f9bee224
google.golang.org/grpc@v1.53.0
1.83.1
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
google.golang.org/grpc@v1.45.0
1.83.1
1
bicarus/wg-access-server:v0.8.206cab48e9334
google.golang.org/grpc@v1.50.1
1.83.1
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
google.golang.org/grpc@v1.63.2
1.83.1
1
binwiederhier/ntfy:v2.6.283e2e43d9956
google.golang.org/grpc@v1.56.1
1.83.1
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
google.golang.org/grpc@v1.65.0
1.83.1
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
google.golang.org/grpc@v1.66.0
1.83.1
1
bitnamilegacy/kube-state-metrics:204a3044b384b
google.golang.org/grpc@v1.68.1
1.83.1
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
google.golang.org/grpc@v1.60.1
1.83.1
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
google.golang.org/grpc@v1.50.1
1.83.1
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
google.golang.org/grpc@v1.65.0
1.83.1
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
google.golang.org/grpc@v1.60.1
1.83.1
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
google.golang.org/grpc@v1.71.0
1.83.1
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
google.golang.org/grpc@v1.71.0
1.83.1
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
google.golang.org/grpc@v1.65.0
1.83.1
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
google.golang.org/grpc@v1.71.0
1.83.1
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
google.golang.org/grpc@v1.67.1
1.83.1
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
google.golang.org/grpc@v1.69.0
1.83.1
1
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
google.golang.org/grpc@v1.71.0
1.83.1
1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
google.golang.org/grpc@v1.65.0
1.83.1
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
google.golang.org/grpc@v1.45.0
1.83.1
1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
google.golang.org/grpc@v1.72.0
1.83.1
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
google.golang.org/grpc@v1.63.2
1.83.1
1
bitnami/mongodb-exporter:latestf7034c13af4e
google.golang.org/grpc@v1.82.1
1.83.1
1
blipai/deckard:0.0.28737d5d19a312
google.golang.org/grpc@v1.53.0
1.83.1
1
blipai/deckard:0.1.8db8cd873d0eb
google.golang.org/grpc@v1.82.0
1.83.1
1
bolkedebruin/rdpgw:masterc0dc0589373a
google.golang.org/grpc@v1.79.3
1.83.1
1
bonovoo/secrethor:1.1.2bb93b68fcd17
google.golang.org/grpc@v1.58.3
1.83.1
1
breton/cool:dev41b1bb483aa2
google.golang.org/grpc@v1.47.0
1.83.1
1
bsgrigorov/helm-operator:latest45ab095f09c8
google.golang.org/grpc@v1.30.0
1.83.1
1
buildkite/agent:3.25.0aec38cfaae0e
google.golang.org/grpc@v0.0.0-20170216003643-d0c32ee6a441
1.83.1
1
bytebase/bytebase:latesta6d845773b60
google.golang.org/grpc@v1.82.1
1.83.1
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
google.golang.org/grpc@v1.55.0
1.83.1
1
calico/cni:v3.28.0cef0c907b8f4
google.golang.org/grpc@v1.61.1
1.83.1
1
calico/cni:v3.28.1e486870cfde8
google.golang.org/grpc@v1.61.1
1.83.1
1
calico/kube-controllers:v3.28.08f04e4772a2b
google.golang.org/grpc@v1.61.1
1.83.1
1
calico/kube-controllers:v3.28.1eadb3a25109a
google.golang.org/grpc@v1.61.1
1.83.1
1
calico/node:v3.28.0385bf6391fea
google.golang.org/grpc@v1.61.1
1.83.1
1
calico/node:v3.28.1d8c644a8a3ee
google.golang.org/grpc@v1.61.1
1.83.1
1
camptocamp/bucket-cloner:latestacfafc308d88
google.golang.org/grpc@v1.37.0
1.83.1
1
casbin/casdoor:v1.753.0770ad9ec3190
google.golang.org/grpc@v1.59.0
1.83.1
1
casbin/casdoor:4.7.09d015582847d
google.golang.org/grpc@v1.79.3
1.83.1
1
castopod/castopod:1.15.54e4f0440520f
google.golang.org/grpc@v1.78.0
1.83.1
1
certimate/certimate:v0.4.326e481dd3d2cf
google.golang.org/grpc@v1.82.1
1.83.1
1
cesanta/docker_auth:1.14.098e0307e0d2d
google.golang.org/grpc@v1.56.3
1.83.1
1
chaosnative/cle-auth-server:2.7.072ee352bc333
google.golang.org/grpc@v1.32.0
1.83.1
1
chaosnative/cle-server:2.7.0e7bcff4a20c0
google.golang.org/grpc@v1.42.0
1.83.1
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
google.golang.org/grpc@v1.81.0
1.83.1
1
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
google.golang.org/grpc@v1.33.1
1.83.1
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.