StackRadar

CVE-2026-84303

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,270
of 17,790 indexed, latest versions
Container images
2,748
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,270 of 17,790 indexed charts deploy, on 2,748 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+114 more1.83.12,745
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed3
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441
Trending
Rank 47 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,270 by stars
ChartLatestAffected imagesRadar Score
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
google.golang.org/grpc@v1.45.0
1.83.1

Open the chart page →

2,234
k8s-cloudwatch-adapterdeliveryheroVerified publisher0.2.21 of 1See more

k8s-cloudwatch-adapter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
google.golang.org/grpc@v1.23.1
1.83.1

Open the chart page →

2,468
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
google.golang.org/grpc@v1.46.0
1.83.1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
google.golang.org/grpc@v1.46.0
1.83.1

Open the chart page →

4,722
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

9,152
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/grpc@v1.15.0
1.83.1
quay.io/dexidp/dex:v2.25.07bcf286807b8
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

10,468
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

12,999
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

1,580
caddy-reverse-proxydevtron0.10.11 of 1See more

caddy-reverse-proxy devtron 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/caddy:latest13ba145cba2f
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

846
devtron-enterprisedevtron48.0.014 of 28See more

devtron-enterprise devtron 48.0.0

14 of the 28 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.83.1
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.83.1
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.83.1
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.83.1
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

66,542
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/grpc@v1.33.1
1.83.1
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

5,041
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/grpc@v1.20.1
1.83.1

Open the chart page →

11,957
kube-prometheus-stackdevtron19.3.02 of 6See more

kube-prometheus-stack devtron 19.3.0

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/grpc@v1.40.0
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

8,645
migrantdevtron0.0.31 of 1See more

migrant devtron 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
migrate/migrate:latest76cc2074cb66
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

105
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

2,435
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

1,507
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

9,152
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/grpc@v1.15.0
1.83.1
quay.io/dexidp/dex:v2.25.07bcf286807b8
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

1,580
caddy-reverse-proxydevtron-labs0.10.11 of 1See more

caddy-reverse-proxy devtron-labs 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/caddy:latestdf7f1c2fb114
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

846
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

10,073
devtron-enterprisedevtron-labs48.0.014 of 28See more

devtron-enterprise devtron-labs 48.0.0

14 of the 28 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.83.1
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.83.1
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.83.1
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.83.1
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/grpc@v1.33.1
1.83.1
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

5,041
devtron-operatordevtron-labs0.23.37 of 11See more

devtron-operator devtron-labs 0.23.3

7 of the 11 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.83.1
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.83.1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.83.1
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.83.1

Open the chart page →

31,447
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/grpc@v1.20.1
1.83.1

Open the chart page →

11,957
kube-prometheus-stackdevtron-labs19.3.02 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/grpc@v1.40.0
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

8,645
migrantdevtron-labs0.0.31 of 1See more

migrant devtron-labs 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
migrate/migrate:latestcc4ad8e19d66
google.golang.org/grpc@v1.74.2
1.83.1

Open the chart page →

734
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

2,435
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

1,507
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

19,063
direktivdirektivVerified publisher0.10.01 of 6See more

direktiv direktiv 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
google.golang.org/grpc@v1.70.0
1.83.1

Open the chart page →

3,470
ownclouddjjudas21Verified publisher0.3.231 of 3See more

owncloud djjudas21 0.3.23

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
owncloud/server:10.16.3b3f9efdcd7f7
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

10,129
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
google.golang.org/grpc@v1.60.0
1.83.1

Open the chart page →

4,217
dnation-kubernetes-monitoring-stackdnationcloud4.0.28 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

8 of the 17 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
google.golang.org/grpc@v1.63.2
1.83.1
grafana/grafana:13.1.0121a7a9ece6d
google.golang.org/grpc@v1.79.3
1.83.1
grafana/loki:3.2.0882e30c20683
google.golang.org/grpc@v1.65.0
1.83.1
grafana/loki-canary:3.2.049e03f80d361
google.golang.org/grpc@v1.65.0
1.83.1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
google.golang.org/grpc@v1.50.1
1.83.1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
google.golang.org/grpc@v1.50.1
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

21,455
docker-authdocker-auth1.14.01 of 1See more

docker-auth docker-auth 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.14.098e0307e0d2d
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

1,506
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

8,408
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
google.golang.org/grpc@v1.32.0
1.83.1

Open the chart page →

3,046
corednsdoubanVerified publisher1.39.21 of 1See more

coredns douban 1.39.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
coredns/coredns:1.12.040384aa1f5ea
google.golang.org/grpc@v1.68.0
1.83.1

Open the chart page →

1,132
gatekeeperdoubanVerified publisher3.17.11 of 3See more

gatekeeper douban 3.17.1

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.17.1b7b4d7cfdd52
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

2,492
goinceptiondoubanVerified publisher0.3.11 of 2See more

goinception douban 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

1,201
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
google.golang.org/grpc@v1.55.0
1.83.1

Open the chart page →

3,660
service-proberdoubanVerified publisher0.1.01 of 1See more

service-prober douban 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

594
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
google.golang.org/grpc@v1.45.0
1.83.1

Open the chart page →

30,759
drogue-cloud-metricsdrogue-iotVerified publisher0.7.112 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

2 of the 8 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
google.golang.org/grpc@v1.45.0
1.83.1
quay.io/prometheus/prometheus:v2.26.038d40a760569
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

13,558
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/cephcsi/ceph-csi-operator:v0.5.014fe2f1bffc3
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

1,990
temporaldtrdnk-helm-chartsVerified publisher0.35.05 of 13See more

temporal dtrdnk-helm-charts 0.35.0

5 of the 13 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
google.golang.org/grpc@v1.23.1
1.83.1
temporalio/admin-tools:1.22.4258958fe2ff2
google.golang.org/grpc@v1.58.2
1.83.1
temporalio/server:1.22.4c0a44c26397b
google.golang.org/grpc@v1.59.0
1.83.1
temporalio/ui:2.16.2af9c9349708f
google.golang.org/grpc@v1.55.0
1.83.1
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

20,204
cloudflaredduck-helm1.1.31 of 1See more

cloudflared duck-helm 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

1,442
duplicacyduplicacy0.1.21 of 2See more

duplicacy duplicacy 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
google.golang.org/grpc@v1.28.1
1.83.1

Open the chart page →

2,413
ai-scale-authdysnixVerified publisher0.1.12 of 3See more

ai-scale-auth dysnix 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
alex6021710/ai-scale-auth:latest6c7a47e470c3
google.golang.org/grpc@v1.42.0
1.83.1
alex6021710/ai-scale-migrator:latest744b8a924f35
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

6,141
ai-scale-doerdysnixVerified publisher0.1.01 of 1See more

ai-scale-doer dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
alex6021710/ai-scale-doer:latest31e533cf7cd3
google.golang.org/grpc@v1.42.0
1.83.1

Open the chart page →

2,801

Container images carrying it

2,748 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
datawire/aes:2.0.3-ea07f8fe4f4f8e
google.golang.org/grpc@v1.34.0
1.83.1
1
datawire/aes:1.13.62beb65062c8b
google.golang.org/grpc@v1.34.0
1.83.1
1
datawire/aes:3.11.195ec30b3c732
google.golang.org/grpc@v1.60.1
1.83.1
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
google.golang.org/grpc@v1.24.0
1.83.1
1
datawire/emissary:3.12.21f67a1292d2a
google.golang.org/grpc@v1.67.0
1.83.1
1
datawire/emissary:2.0.2-ea9716efbdd24b
google.golang.org/grpc@v1.34.0
1.83.1
1
ddosify/alaz:v0.12.0ea602056d9ce
google.golang.org/grpc@v1.59.0
1.83.1
1
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
google.golang.org/grpc@v1.54.0
1.83.1
1
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
google.golang.org/grpc@v1.53.0
1.83.1
1
defactops/defactops-ui:1.0.16825cdf9ba706
google.golang.org/grpc@v1.62.1
1.83.1
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
google.golang.org/grpc@v1.48.0
1.83.1
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
google.golang.org/grpc@v1.42.0
1.83.1
1
devopsfaith/krakend:2.6.34c678c224f67
google.golang.org/grpc@v1.63.2
1.83.1
1
devopsfaith/krakend:2.7.09219cda867e2
google.golang.org/grpc@v1.63.2
1.83.1
1
devopstales/trivy-operator:2.575136aa7a26e
google.golang.org/grpc@v1.50.1
1.83.1
1
devsecurely/cview-issuer:0.0.42eecd4314e933
google.golang.org/grpc@v1.81.0
1.83.1
1
devspacecloud/manager:0.3.349c397413f7b
google.golang.org/grpc@v1.27.0
1.83.1
1
dexidp/dex:v2.39.1-distroless43655afd1a8f
google.golang.org/grpc@v1.62.1
1.83.1
1
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
google.golang.org/grpc@v1.27.1
1.83.1
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
google.golang.org/grpc@v1.56.3
1.83.1
1
distribution/distribution:3.1.1bca24727f400
google.golang.org/grpc@v1.80.0
1.83.1
1
dockerdaemon0901/rolldice:v14e5bfe179c7e
google.golang.org/grpc@v1.59.0
1.83.1
1
dollarshaveclub/furan2:master14a257836529
google.golang.org/grpc@v1.32.0
1.83.1
1
dollarshaveclub/thermite:0.0.31663cbf25fcfe
google.golang.org/grpc@v1.40.0
1.83.1
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
google.golang.org/grpc@v1.56.0
1.83.1
1
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
google.golang.org/grpc@v1.53.0
1.83.1
1
dongjiang1989/pingmesh-agent:latest355fa4be8e97
google.golang.org/grpc@v1.67.0
1.83.1
1
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
google.golang.org/grpc@v1.67.0
1.83.1
1
dragonflyoss/client:v1.5.4a1b52779c4dd
google.golang.org/grpc@v1.81.1
1.83.1
1
dragonflyoss/client:v0.1.82edf3e921f4e0
google.golang.org/grpc@v1.60.1
1.83.1
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
google.golang.org/grpc@v1.64.0
1.83.1
1
dragonflyoss/scheduler:v2.1.49523785c77787
google.golang.org/grpc@v1.64.0
1.83.1
1
dragonflyoss/scheduler:v2.5.2-rc.06d710dc2bae0
google.golang.org/grpc@v1.79.3
1.83.1
1
drone/drone:2.28.255897c8fb22d
google.golang.org/grpc@v1.59.0
1.83.1
1
drone/drone-runner-docker:1.8.1137e79c5e23c
google.golang.org/grpc@v1.29.1
1.83.1
1
drumsergio/duplicacy-container:0.1.0dd3ee9703969
google.golang.org/grpc@v1.28.1
1.83.1
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/grpc@v1.49.0
1.83.1
1
dunglas/mercure:v0.24.080fcb704a741
google.golang.org/grpc@v1.81.0
1.83.1
1
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
google.golang.org/grpc@v1.56.3
1.83.1
1
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
google.golang.org/grpc@v1.40.0
1.83.1
1
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
google.golang.org/grpc@v1.27.0
1.83.1
1
eginnovations/agent:7.5.4e4dfe242fe9f
google.golang.org/grpc@v1.80.0
1.83.1
1
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
google.golang.org/grpc@v1.68.1
1.83.1
1
elastic/apm-server:7.17.6c7a1c63257d0
google.golang.org/grpc@v1.48.0
1.83.1
1
elastiflow/flow-collector:7.26.0fee67842e16b
google.golang.org/grpc@v1.81.0
1.83.1
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
google.golang.org/grpc@v1.82.1
1.83.1
1
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
google.golang.org/grpc@v1.68.1
1.83.1
1
emqx/ecp-main:2.5.1fa876f71e5d6
google.golang.org/grpc@v1.67.1
1.83.1
1
emqxecp/otelcol:2.5.04c31d9bec846
google.golang.org/grpc@v1.66.0
1.83.1
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
google.golang.org/grpc@v1.31.0
1.83.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.