StackRadar

CVE-2026-84303

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,293
of 17,787 indexed, latest versions
Container images
2,768
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,293 of 17,787 indexed charts deploy, on 2,768 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,764
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Trending
Rank 41 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,293 by stars
ChartLatestAffected imagesRadar Score
mercuremercureOfficialVerified publisher0.24.01 of 1See more

mercure mercure 0.24.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dunglas/mercure:v0.24.080fcb704a741
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

1,409
meshery-operatormesheryOfficialVerified publisher1.0.702 of 2See more

meshery-operator meshery 1.0.70

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
alpine/k8s:1.35.6b7a12c5ddf26
google.golang.org/grpc@v1.81.0
1.83.1
meshery/meshery-operator:1.0.50d245bc8b5c6
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

2,416
missing-container-metricsmissing-container-metrics0.1.11 of 1See more

missing-container-metrics missing-container-metrics 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

2,409
olmolmVerified publisher0.45.01 of 1See more

olm olm 0.45.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/operator-framework/olm:v0.45.0f228c7a6b8c5
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

433
opencostopencost-ociOfficialVerified publisher2.5.311 of 2See more

opencost opencost-oci 2.5.31

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost:1.121.2de2784434527
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

266
ketoory0.64.01 of 1See more

keto ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
oryd/keto:v26.2.0bfdb8b9e283a
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

817
oathkeeperory0.64.01 of 1See more

oathkeeper ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
oryd/oathkeeper:v26.2.0467329abde34
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

769
pmmpercona1.9.11 of 1See more

pmm percona 1.9.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
percona/pmm-server:3.9.1003f9c25f842
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

790
redis-enterprise-operatorredis-enterprise-operator-officialOfficialVerified publisher8.0.18-111 of 1See more

redis-enterprise-operator redis-enterprise-operator-official 8.0.18-11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
redislabs/operator:8.0.18-119078e713bb6a
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

914
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,357
rekorsigstoreVerified publisher1.8.54 of 9See more

rekor sigstore 1.8.5

4 of the 9 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/sigstore/rekor/rekor-server:v1.5.4100d793d68d0
google.golang.org/grpc@v1.82.1
1.83.1
ghcr.io/sigstore/scaffolding/createtreedigest-pinnede5232e8c9122
google.golang.org/grpc@v1.76.0
1.83.1
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
google.golang.org/grpc@v1.82.0
1.83.1
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

5,416
snyk-monitorsnyk2.23.261 of 2See more

snyk-monitor snyk 2.23.26

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
snyk/kubernetes-monitor:2.23.26fb5ad76ce84e
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

578
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.03 of 3See more

swo-k8s-collector solarwinds 5.3.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
google.golang.org/grpc@v1.81.1
1.83.1
ghcr.io/open-telemetry/opentelemetry-ebpf-instrumentation/ebpf-instrument:v0.9.026f82b148dfe
google.golang.org/grpc@v1.80.0
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

2,347
sops-operatorsops-operatorVerified publisher0.10.11 of 2See more

sops-operator sops-operator 0.10.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/sops-operator:0.10.11da9b716b792
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

1,250
thehivestrangebee-helmOfficialVerified publisher1.0.62 of 7See more

thehive strangebee-helm 1.0.6

2 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
google.golang.org/grpc@v1.71.0
1.83.1
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
google.golang.org/grpc@v1.71.0
1.83.1

Open the chart page →

16,161
truenas-csptruenas-cspVerified publisher1.2.410 of 11See more

truenas-csp truenas-csp 1.2.4

10 of the 11 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/hpestorage/csi-driver:v3.2.0ef7f4e1544fa
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/hpestorage/csi-extensions:v1.2.1189146672a7ac
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/hpestorage/volume-group-provisioner:v1.0.107bf9d8f16a5d
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/hpestorage/volume-group-snapshotter:v1.0.10caeaaffe7e2b
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/hpestorage/volume-mutator:v1.3.109e98b2e697bd
google.golang.org/grpc@v1.79.3
1.83.1
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
google.golang.org/grpc@v1.79.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
google.golang.org/grpc@v1.78.0
1.83.1

Open the chart page →

5,851
uffizzi-controlleruffizzi-controller2.4.62 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

2 of the 11 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
google.golang.org/grpc@v1.60.1
1.83.1
quay.io/jetstack/cert-manager-webhook:v1.14.5ef419261a209
google.golang.org/grpc@v1.60.1
1.83.1

Open the chart page →

14,266
vsphere-csivsphere-tmm3.8.17 of 7See more

vsphere-csi vsphere-tmm 3.8.1

7 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
google.golang.org/grpc@v1.68.1
1.83.1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
google.golang.org/grpc@v1.68.1
1.83.1
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
google.golang.org/grpc@v1.69.4
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
google.golang.org/grpc@v1.69.0
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
google.golang.org/grpc@v1.60.0
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
google.golang.org/grpc@v1.69.2
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

3,911
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

6,168
kubedbappscodeVerified publisher2026.7.107 of 8See more

kubedb appscode 2026.7.10

7 of the 8 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/appscode/petset:v0.1.093fa0daf603c
google.golang.org/grpc@v1.72.1
1.83.1
ghcr.io/appscode/sidekick:v0.0.15d1036b07e348
google.golang.org/grpc@v1.72.1
1.83.1
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
google.golang.org/grpc@v1.79.3
1.83.1
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
google.golang.org/grpc@v1.79.3
1.83.1
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
google.golang.org/grpc@v1.79.3
1.83.1
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
google.golang.org/grpc@v1.79.3
1.83.1
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

4,048
cloudflaredartur9010Verified publisher1.0.91 of 3See more

cloudflared artur9010 1.0.9

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

2,990
alb-controllerazure-application-gateway-for-containers1.12.12 of 3See more

alb-controller azure-application-gateway-for-containers 1.12.1

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
mcr.microsoft.com/application-lb/images/alb-controller:1.12.172f33b24bc67
google.golang.org/grpc@v1.82.1
1.83.1
mcr.microsoft.com/application-lb/images/alb-controller-bootstrap:1.12.1cc129fd1c904
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

209
baserowbaserow-chartVerified publisher1.0.562 of 6See more

baserow baserow-chart 1.0.56

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
google.golang.org/grpc@v1.65.0
1.83.1
caddy/ingress:v0.2.118d1366fc0e9
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

17,346
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
google.golang.org/grpc@v1.51.0
1.83.1

Open the chart page →

1,698
celestia-appcelestia-labsVerified publisher0.5.01 of 3See more

celestia-app celestia-labs 0.5.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
google.golang.org/grpc@v1.68.0
1.83.1

Open the chart page →

1,066
cert-manager-webhook-hetznercert-manager-webhook-hetznerVerified publisher0.2.11 of 1See more

cert-manager-webhook-hetzner cert-manager-webhook-hetzner 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

3,080
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
google.golang.org/grpc@v1.33.1
1.83.1
library/traefik:2.5.47d0228d19042
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

53,012
openstack-cloud-controller-managercloud-provider-openstack2.36.51 of 1See more

openstack-cloud-controller-manager cloud-provider-openstack 2.36.5

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/openstack-cloud-controller-manager:v1.36.0e354e40db2d0
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

498
cloudquerycloudquery39.0.41 of 1See more

cloudquery cloudquery 39.0.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cloudquery/cloudquery:6.40.040b804fce7f9
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

544
cluster-api-operatorcluster-api-operator0.29.01 of 1See more

cluster-api-operator cluster-api-operator 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/capi-operator/cluster-api-operator:v0.29.0465e72f8b06a
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

41
immudbcodenotaryVerified publisher1.9.71 of 1See more

immudb codenotary 1.9.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
codenotary/immudb:1.9.77c85d7cc4f22
google.golang.org/grpc@v1.57.1
1.83.1

Open the chart page →

1,247
routercosmo-routerOfficialVerified publisher0.18.01 of 1See more

router cosmo-router 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

1,669
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
wait4x/wait4x:3.3.14dcd86307de1
google.golang.org/grpc@v1.71.0
1.83.1

Open the chart page →

9,154
csi-wekafsplugincsi-wekafsOfficialVerified publisher0.6.2-01 of 6See more

csi-wekafsplugin csi-wekafs 0.6.2-0

1 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
google.golang.org/grpc@v1.10.0
1.83.1

Open the chart page →

2,824
daskhubdask2024.1.12 of 9See more

daskhub dask 2024.1.1

2 of the 9 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/traefik:2.10.61957e3314f43
google.golang.org/grpc@v1.58.3
1.83.1
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

14,134
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

27,358
drone-runner-dockerdroneVerified publisher0.7.02 of 3See more

drone-runner-docker drone 0.7.0

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
drone/drone-runner-docker:1.8.1137e79c5e23c
google.golang.org/grpc@v1.29.1
1.83.1
library/docker:20-dindaf96c680a7e1
google.golang.org/grpc@v1.50.1
1.83.1

Open the chart page →

5,674
k8s-image-swapperestahnVerified publisher1.11.01 of 2See more

k8s-image-swapper estahn 1.11.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

1,980
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

1,760
flannelflannel0.28.91 of 2See more

flannel flannel 0.28.9

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/flannel-io/flannel:v0.28.9708a2c9c1cfb
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

610
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
google.golang.org/grpc@v1.41.0
1.83.1
thesisrobot/loop:v0.11.1-beta89ae07e787ca
google.golang.org/grpc@v1.24.0
1.83.1
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

8,834
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

1,738
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.22.1e8cad21b2f9a
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

2,800
alloy-operatorgrafana0.7.11 of 1See more

alloy-operator grafana 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

420
grafana-mcpgrafana-communityVerified publisher0.23.21 of 1See more

grafana-mcp grafana-community 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/mcp-grafana:1.4.2f87fa67a561f
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

1,009
klusterviewklusterviewVerified publisher0.1.02 of 4See more

klusterview klusterview 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

3,796
gateway-operatorkongOfficialVerified publisher0.6.11 of 1See more

gateway-operator kong 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kong/gateway-operator:1.603510967482b
google.golang.org/grpc@v1.71.1
1.83.1

Open the chart page →

842
kubeflowkubeflow1.6.218 of 45See more

kubeflow kubeflow 1.6.2

18 of the 45 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
google.golang.org/grpc@v1.36.0
1.83.1
istio/proxyv2:1.14.1df69c1a7af7c
google.golang.org/grpc@v1.45.0
1.83.1
kserve/kserve-controller:v0.8.0f0692a9ea09f
google.golang.org/grpc@v1.42.0
1.83.1
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
google.golang.org/grpc@v1.42.0
1.83.1
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
google.golang.org/grpc@v1.42.0
1.83.1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
google.golang.org/grpc@v1.42.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
google.golang.org/grpc@v1.44.0
1.83.1
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

97,040
testkubekubeshop2.13.21 of 5See more

testkube kubeshop 2.13.2

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kubeshop/testkube-minio:2025.10d8e1af6aca99
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

5,012
openelbkubesphere-stable0.5.01 of 2See more

openelb kubesphere-stable 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

4,329

Container images carrying it

2,768 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
flomesh/osm-edge-controller:1.3.9add7a4da4622
google.golang.org/grpc@v1.51.0
1.83.1
1
flomesh/osm-edge-injector:1.3.947287e3ad324
google.golang.org/grpc@v1.51.0
1.83.1
1
fluxcd/flux-cli:v2.9.5704d55295355
google.golang.org/grpc@v1.80.0
1.83.1
1
fluxcd/helm-controller:v0.9.092b891e495d8
google.golang.org/grpc@v1.27.1
1.83.1
1
fluxcd/source-controller:v0.10.031a8c79a6803
google.golang.org/grpc@v1.27.1
1.83.1
1
fluxninja/aperture-operator:2.34.0356d7aa86632
google.golang.org/grpc@v1.60.1
1.83.1
1
foomo/contentserver:1.21.0824f41463e9b
google.golang.org/grpc@v1.82.1
1.83.1
1
fortio/fortio:latest_releasefc8221136fe2
google.golang.org/grpc@v1.72.1
1.83.1
1
fosrl/newt:1.10.4ccd2b0e9a049
google.golang.org/grpc@v1.79.1
1.83.1
1
foxcpp/maddy:0.7.16ab538e2f28b
google.golang.org/grpc@v1.60.1
1.83.1
1
foxcpp/maddy:0.9.2a4b839985b9b
google.golang.org/grpc@v1.70.0
1.83.1
1
foxcpp/maddy:0.8.2eeb5813fc4d1
google.golang.org/grpc@v1.70.0
1.83.1
1
galaxy/cloudman-server:lateste5c265fe9fcd
google.golang.org/grpc@v1.43.0
1.83.1
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
google.golang.org/grpc@v1.67.0
1.83.1
1
garethgeorge/backrest:v1.14.1b85297975428
google.golang.org/grpc@v1.81.1
1.83.1
1
gboxproxy/gbox:v1.0.63a9f4a711d5c
google.golang.org/grpc@v1.44.0
1.83.1
1
gdxbsv/traktor:0.0.17675693335054
google.golang.org/grpc@v1.68.1
1.83.1
1
getconvoy/convoy:v26.7.6f4934cc05e31
google.golang.org/grpc@v1.80.0
1.83.1
1
gidoichi/secrets-store-csi-driver-provider-infisical:v1.1.42dd5322a0610
google.golang.org/grpc@v1.83.0
1.83.1
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
google.golang.org/grpc@v1.62.0
1.83.1
1
gitea/gitea:1.27.3-rootless1c17ecaead42
google.golang.org/grpc@v1.81.1
1.83.1
1
gitea/gitea:1.27.134e3f6b75f5c
google.golang.org/grpc@v1.81.1
1.83.1
1
gitea/gitea:1.22.376f516a1a8c2
google.golang.org/grpc@v1.62.1
1.83.1
1
gitea/gitea:1.26.27d13848af126
google.golang.org/grpc@v1.79.3
1.83.1
1
gitea/gitea:1.27.387a67ee09d3a
google.golang.org/grpc@v1.81.1
1.83.1
1
gitea/gitea:1.21.6ac73e0da341f
google.golang.org/grpc@v1.58.3
1.83.1
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
google.golang.org/grpc@v1.34.0
1.83.1
1
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
google.golang.org/grpc@v1.21.1
1.83.1
1
goalert/goalert:v0.32.008d57388b0cb
google.golang.org/grpc@v1.61.0
1.83.1
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
google.golang.org/grpc@v1.69.4
1.83.1
1
goccx/go-file-server:latestf4b3ebea0303
google.golang.org/grpc@v1.65.0
1.83.1
1
gocrane/craned:v0.5.1a1400909118c
google.golang.org/grpc@v1.43.0
1.83.1
1
gocrane/crane-scheduler:0.0.239ba6d11b2079
google.golang.org/grpc@v1.40.0
1.83.1
1
gogost/gost:3.3.0f7a958c45192
google.golang.org/grpc@v1.82.1
1.83.1
1
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
google.golang.org/grpc@v1.43.0
1.83.1
1
goharbor/harbor-acceld:0.2.13451103a6c8d8
google.golang.org/grpc@v1.59.0
1.83.1
1
goharbor/harbor-core:v2.9.06412d679fdc3
google.golang.org/grpc@v1.53.0
1.83.1
1
goharbor/harbor-core:v2.5.386bf3031f4a7
google.golang.org/grpc@v1.41.0
1.83.1
1
goharbor/harbor-core:v2.14.3a30e5a8be3d9
google.golang.org/grpc@v1.69.4
1.83.1
1
goharbor/harbor-core:v2.11.1c017dd84ee96
google.golang.org/grpc@v1.63.2
1.83.1
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
google.golang.org/grpc@v1.53.0
1.83.1
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
google.golang.org/grpc@v1.41.0
1.83.1
1
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
google.golang.org/grpc@v1.69.4
1.83.1
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
google.golang.org/grpc@v1.41.0
1.83.1
1
goharbor/harbor-registryctl:v2.9.0cce272836449
google.golang.org/grpc@v1.53.0
1.83.1
1
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
google.golang.org/grpc@v1.69.4
1.83.1
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
google.golang.org/grpc@v1.27.1
1.83.1
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
google.golang.org/grpc@v1.27.1
1.83.1
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
google.golang.org/grpc@v1.78.0
1.83.1
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
google.golang.org/grpc@v1.47.0
1.83.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.