StackRadar

CVE-2026-84303

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,293
of 17,787 indexed, latest versions
Container images
2,768
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,293 of 17,787 indexed charts deploy, on 2,768 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,764
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Trending
Rank 41 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,293 by stars
ChartLatestAffected imagesRadar Score
volsyncbackube-helm-chartsVerified publisher0.16.01 of 1See more

volsync backube-helm-charts 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/backube/volsync:0.16.00d03a6aad575
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,364
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
concourse/concourse:8.3.040a143ce5873
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

2,034
dynatrace-operatordynatraceVerified publisher1.10.21 of 1See more

dynatrace-operator dynatrace 1.10.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.10.252281db48c93
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

165
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
google.golang.org/grpc@v1.31.0
1.83.1

Open the chart page →

4,159
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

1,985
oncallgrafana1.16.54 of 12See more

oncall grafana 1.16.5

4 of the 12 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
google.golang.org/grpc@v1.64.0
1.83.1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
google.golang.org/grpc@v1.43.0
1.83.1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
google.golang.org/grpc@v1.43.0
1.83.1
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

16,251
k8sgpt-operatork8sgptOfficialVerified publisher0.2.292 of 2See more

k8sgpt-operator k8sgpt 0.2.29

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.2982d0adcce816
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

966
node-feature-discoverynode-feature-discoveryOfficialVerified publisher0.19.01 of 1See more

node-feature-discovery node-feature-discovery 0.19.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/nfd/node-feature-discovery:v0.19.02fa1c99ad09b
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

207
openbaoopenbaoVerified publisher0.29.41 of 2See more

openbao openbao 0.29.4

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/openbao/openbao:2.6.211fd73a2102c
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

1,509
kratosory0.64.01 of 1See more

kratos ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
oryd/kratos:v26.2.02a13bb8d362c
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

866
sftpgosftpgoOfficialVerified publisher0.47.01 of 1See more

sftpgo sftpgo 0.47.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.46cb60f08fede
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

1,224
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

11,402
aws-cloudwatch-metricsaws0.0.111 of 1See more

aws-cloudwatch-metrics aws 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
google.golang.org/grpc@v1.57.0
1.83.1

Open the chart page →

1,556
csi-driver-smbcsi-driver-smbVerified publisher1.20.35 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

5 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
google.golang.org/grpc@v1.79.3
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

2,952
daprdapr1.18.45 of 5See more

dapr dapr 1.18.4

5 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dapr/injector:1.18.45ac0db7ca106
google.golang.org/grpc@v1.82.1
1.83.1
ghcr.io/dapr/operator:1.18.4af58fae3e7c9
google.golang.org/grpc@v1.82.1
1.83.1
ghcr.io/dapr/placement:1.18.490d2293f42a3
google.golang.org/grpc@v1.82.1
1.83.1
ghcr.io/dapr/scheduler:1.18.4239eac864320
google.golang.org/grpc@v1.82.1
1.83.1
ghcr.io/dapr/sentry:1.18.405286fc952e7
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

175
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
google.golang.org/grpc@v1.34.0
1.83.1

Open the chart page →

4,918
hpe-csi-driverhpe-storageVerified publisher3.3.09 of 14See more

hpe-csi-driver hpe-storage 3.3.0

9 of the 14 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/hpestorage/csi-extensions:v1.3.0df65cea35805
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/hpestorage/volume-group-provisioner:v1.1.09ba017780f80
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/hpestorage/volume-group-snapshotter:v1.1.0b26660528928
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/hpestorage/volume-mutator:v1.4.03890d0b3aa89
google.golang.org/grpc@v1.82.1
1.83.1
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
google.golang.org/grpc@v1.79.3
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

1,633
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
google.golang.org/grpc@v1.75.1
1.83.1

Open the chart page →

2,360
cloudflaredkubitodevVerified publisher1.7.91 of 1See more

cloudflared kubitodev 1.7.9

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

1,442
trident-operatornetapp-tridentVerified publisher100.2606.11 of 1See more

trident-operator netapp-trident 100.2606.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
netapp/trident-operator:26.06.15e8ba78f4ab1
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

47
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

5,278
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

3,031
netbirdjaconiVerified publisher0.15.13 of 4See more

netbird jaconi 0.15.1

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
google.golang.org/grpc@v1.64.1
1.83.1
netbirdio/relay:0.45.1872e3add0e1e
google.golang.org/grpc@v1.64.1
1.83.1
netbirdio/signal:0.45.146ce5a45538f
google.golang.org/grpc@v1.64.1
1.83.1

Open the chart page →

8,473
k8upk8upVerified publisher4.10.01 of 1See more

k8up k8up 4.10.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.16.029458113b8b6
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

717
linkerd-jaegerlinkerd2Verified publisher30.12.112 of 4See more

linkerd-jaeger linkerd2 30.12.11

2 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
google.golang.org/grpc@v1.44.0
1.83.1
otel/opentelemetry-collector:0.59.0ee9da0b08d83
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

4,405
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

9,697
open-feature-operatoropen-feature-operatorOfficialVerified publisher0.9.31 of 1See more

open-feature-operator open-feature-operator 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/open-feature/open-feature-operator:v0.9.3b37a442c0497
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

128
telepresence-osstelepresence-ossOfficialVerified publisher2.31.21 of 2See more

telepresence-oss telepresence-oss 2.31.2

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/telepresenceio/tel2:2.31.26f1d705594ba
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

1,037
trivytrivy-operator0.26.01 of 1See more

trivy trivy-operator 0.26.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
aquasec/trivy:0.74.062b1e65e8869
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

431
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

1,023
cert-manager-webhook-ovhcert-manager-webhook-ovhVerified publisher0.9.161 of 1See more

cert-manager-webhook-ovh cert-manager-webhook-ovh 0.9.16

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/aureq/cert-manager-webhook-ovh:0.9.160339cf9a75ca
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

196
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
google.golang.org/grpc@v1.34.0
1.83.1

Open the chart page →

5,173
falcosidekickfalcosecurity0.14.01 of 1See more

falcosidekick falcosecurity 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.32.01976da721518
google.golang.org/grpc@v1.75.0
1.83.1

Open the chart page →

1,634
glasskube-operatorglasskubeOfficialVerified publisher0.12.22 of 3See more

glasskube-operator glasskube 0.12.2

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
google.golang.org/grpc@v1.58.0
1.83.1
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
google.golang.org/grpc@v1.58.0
1.83.1

Open the chart page →

11,971
beylagrafana1.16.111 of 1See more

beyla grafana 1.16.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/beyla:3.32.03ff0f7cf2bbf
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

123
helm-dashboardkomodorVerified publisher2.0.71 of 1See more

helm-dashboard komodor 2.0.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
komodorio/helm-dashboard:2.1.3258a9044e658
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

309
kubescape-operatorkubescape1.40.44 of 6See more

kubescape-operator kubescape 1.40.4

4 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/kubescape/kubevuln:v0.3.4309bed2f723ea0
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/kubescape/operator:v0.2.16901b2694425e9
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/kubescape/storage:v0.0.33101f2b053ace1
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

920
linkerd-vizlinkerd2-edgeVerified publisher30.14.11-edge1 of 5See more

linkerd-viz linkerd2-edge 30.14.11-edge

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.1a67e5e402ff5
google.golang.org/grpc@v1.58.3
1.83.1

Open the chart page →

1,346
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
google.golang.org/grpc@v1.71.0
1.83.1
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
google.golang.org/grpc@v1.71.0
1.83.1

Open the chart page →

4,854
milvusmilvus-helm5.0.282 of 4See more

milvus milvus-helm 5.0.28

2 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.25-r1fededb2f2d63
google.golang.org/grpc@v1.71.1
1.83.1
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

10,764
coreneuvectorchartsVerified publisher2.11.12 of 5See more

core neuvectorcharts 2.11.1

2 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
neuvector/controller:5.6.1ae45c394f1ac
google.golang.org/grpc@v1.82.1
1.83.1
neuvector/enforcer:5.6.1aa2137cc90ec
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

884
opa-kube-mgmtopa-kube-mgmtVerified publisher11.0.121 of 2See more

opa-kube-mgmt opa-kube-mgmt 11.0.12

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
openpolicyagent/opa:1.19.0852359995443
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

602
redis-operatorot-container-kit0.26.11 of 1See more

redis-operator ot-container-kit 0.26.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/opstree/redis-operator:v0.26.01c6818e5e505
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

123
spirespiffeVerified publisher0.30.27 of 10See more

spire spiffe 0.30.2

7 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
google.golang.org/grpc@v1.83.0
1.83.1
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
google.golang.org/grpc@v1.71.0
1.83.1
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
google.golang.org/grpc@v1.76.0
1.83.1
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
google.golang.org/grpc@v1.83.0
1.83.1
ghcr.io/spiffe/spire-controller-manager:0.7.0d7b9e710f542
google.golang.org/grpc@v1.82.1
1.83.1
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
google.golang.org/grpc@v1.83.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

1,640
bytebasebytebase1.1.51 of 1See more

bytebase bytebase 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
bytebase/bytebase:latest9fcde38c0d5f
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

436
cert-manager-csi-drivercert-managerOfficialVerified publisher0.16.03 of 3See more

cert-manager-csi-driver cert-manager 0.16.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-csi-driver:v0.16.09d13db6dc80e
google.golang.org/grpc@v1.83.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

489
ansible-semaphorecloudhippieVerified publisher15.2.101 of 1See more

ansible-semaphore cloudhippie 15.2.10

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.19.1498ad9bc7a2a0
google.golang.org/grpc@v1.76.0
1.83.1

Open the chart page →

1,235
etcdcloudpirates-etcdVerified publisher0.8.81 of 1See more

etcd cloudpirates-etcd 0.8.8

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gcr.io/etcd-development/etcd:v3.7.1a9983dd6d928
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

128
codefreshcodefresh-onpremOfficialVerified publisher2.12.133 of 42See more

codefresh codefresh-onprem 2.12.13

3 of the 42 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
google.golang.org/grpc@v1.65.0
1.83.1
ghcr.io/helm/chartmuseum:v0.16.648bc27743c08
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/codefresh/dind:3.0.250885ab519dac
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

14,615
aws-ebs-csi-driverdeliveryheroVerified publisher2.17.46 of 6See more

aws-ebs-csi-driver deliveryhero 2.17.4

6 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
google.golang.org/grpc@v1.51.0
1.83.1
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
google.golang.org/grpc@v1.51.0
1.83.1
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
google.golang.org/grpc@v1.51.0
1.83.1
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
google.golang.org/grpc@v1.51.0
1.83.1
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
google.golang.org/grpc@v1.49.0
1.83.1
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
google.golang.org/grpc@v1.51.0
1.83.1

Open the chart page →

6,485

Container images carrying it

2,768 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
google.golang.org/grpc@v1.55.0
1.83.1
1
gomods/athens:v0.17.10f61d1e62359
google.golang.org/grpc@v1.80.0
1.83.1
1
gomods/athens:v0.18.197cc113b34b0
google.golang.org/grpc@v1.81.1
1.83.1
1
gomods/athens:v0.8.1d714c7ff0231
google.golang.org/grpc@v1.20.1
1.83.1
1
gomods/athens:v0.11.0efb811df7844
google.golang.org/grpc@v1.26.0
1.83.1
1
gotenberg/gotenberg:8.30206a6c708fc6
google.golang.org/grpc@v1.79.3
1.83.1
1
gotenberg/gotenberg:8.3467097317623a
google.golang.org/grpc@v1.81.1
1.83.1
1
gotenberg/gotenberg:8-chromiuma40f92d7419a
google.golang.org/grpc@v1.83.0
1.83.1
1
grafana/agent:v0.44.23364714a2f64
google.golang.org/grpc@v1.66.0
1.83.1
1
grafana/agent:v0.20.0825c09373d27
google.golang.org/grpc@v1.41.0
1.83.1
1
grafana/agent:v0.40.3f6cbec9409be
google.golang.org/grpc@v1.61.0
1.83.1
1
grafana/agent-operator:v0.34.1045c9125634c
google.golang.org/grpc@v1.45.0
1.83.1
1
grafana/alloy:v1.5.101a63f4e032c
google.golang.org/grpc@v1.67.1
1.83.1
1
grafana/alloy:v1.4.306bdcbb51fc2
google.golang.org/grpc@v1.65.0
1.83.1
1
grafana/alloy:v1.18.10f4434c92b3e
google.golang.org/grpc@v1.82.1
1.83.1
1
grafana/alloy:v1.18.0491b0578c049
google.golang.org/grpc@v1.81.1
1.83.1
1
grafana/alloy:v1.16.384b76d56c594
google.golang.org/grpc@v1.80.0
1.83.1
1
grafana/alloy:v1.11.38c7256f412fe
google.golang.org/grpc@v1.75.0
1.83.1
1
grafana/alloy:v1.19.2b8ec653c4423
google.golang.org/grpc@v1.83.0
1.83.1
1
grafana/alloy:v1.1.1c3dac4e26471
google.golang.org/grpc@v1.63.2
1.83.1
1
grafana/alloy:v1.14.0f50931848bd8
google.golang.org/grpc@v1.78.0
1.83.1
1
grafana/beyla:1.3.336d07f8d276e
google.golang.org/grpc@v1.61.0
1.83.1
1
grafana/beyla:3.32.03ff0f7cf2bbf
google.golang.org/grpc@v1.82.1
1.83.1
1
grafana/beyla-k8s-cache:253b2f561cb1b
google.golang.org/grpc@v1.77.0
1.83.1
1
grafana/cloudcost-exporter:v1.12.0eeb2cfecb23e
google.golang.org/grpc@v1.81.1
1.83.1
1
grafana/grafana:6.6.0052147d7e0ec
google.golang.org/grpc@v1.23.1
1.83.1
1
grafana/grafana:10.1.50679e877ba20
google.golang.org/grpc@v1.45.0
1.83.1
1
grafana/grafana:7.5.609bb407e26ab
google.golang.org/grpc@v1.36.0
1.83.1
1
grafana/grafana:13.0.10f86bada30d6
google.golang.org/grpc@v1.79.3
1.83.1
1
grafana/grafana:7.3.315b977f5207d
google.golang.org/grpc@v1.30.0
1.83.1
1
grafana/grafana:9.4.71a359d92f40e
google.golang.org/grpc@v1.45.0
1.83.1
1
grafana/grafana:10.1.11b9ca4bbc4a2
google.golang.org/grpc@v1.45.0
1.83.1
1
grafana/grafana:13.0.1-security-012d1f9ae67c17
google.golang.org/grpc@v1.79.3
1.83.1
1
grafana/grafana:12.2.22ebef928d7e5
google.golang.org/grpc@v1.74.2
1.83.1
1
grafana/grafana:12.2.135c41e0fd029
google.golang.org/grpc@v1.74.2
1.83.1
1
grafana/grafana:9.5.239c849cebccc
google.golang.org/grpc@v1.45.0
1.83.1
1
grafana/grafana:11.2.2-security-01464eac539793
google.golang.org/grpc@v1.65.0
1.83.1
1
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
1
grafana/grafana:11.6.062d2b9d20a19
google.golang.org/grpc@v1.70.0
1.83.1
1
grafana/grafana:8.0.3696823fbc561
google.golang.org/grpc@v1.37.1
1.83.1
1
grafana/grafana:10.2.36b5b37eb35bb
google.golang.org/grpc@v1.59.0
1.83.1
1
grafana/grafana:7.3.46d42886b3ebe
google.golang.org/grpc@v1.30.0
1.83.1
1
grafana/grafana:12.3.070d9599b186c
google.golang.org/grpc@v1.76.0
1.83.1
1
grafana/grafana:7.2.1733842cca5bd
google.golang.org/grpc@v1.30.0
1.83.1
1
grafana/grafana:12.2.074144189b384
google.golang.org/grpc@v1.74.2
1.83.1
1
grafana/grafana:9.4.376dcf36e7d2a
google.golang.org/grpc@v1.45.0
1.83.1
1
grafana/grafana:10.3.38640e5038e83
google.golang.org/grpc@v1.60.1
1.83.1
1
grafana/grafana:11.5.28b37a2f028f1
google.golang.org/grpc@v1.69.2
1.83.1
1
grafana/grafana:9.1.19746858c20e6
google.golang.org/grpc@v1.45.0
1.83.1
1
grafana/grafana:12.1.1a1701c218024
google.golang.org/grpc@v1.73.0
1.83.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.