StackRadar

CVE-2026-84303

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,288
of 17,790 indexed, latest versions
Container images
2,765
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,288 of 17,790 indexed charts deploy, on 2,765 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,761
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441
Trending
Rank 47 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,288 by stars
ChartLatestAffected imagesRadar Score
datadog-csi-driverdatadogVerified publisher0.17.02 of 2See more

datadog-csi-driver datadog 0.17.0

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gcr.io/datadoghq/csi-driver:1.4.086c713de81d9
google.golang.org/grpc@v1.83.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

2,055
agent-helmdatasaker0.1.85 of 6See more

agent-helm datasaker 0.1.8

5 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
datasaker/dsk-container-agent:latest08b52999f67b
google.golang.org/grpc@v1.57.0
1.83.1
datasaker/dsk-k8s-agent:latest2542ee73be51
google.golang.org/grpc@v1.50.1
1.83.1
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
google.golang.org/grpc@v1.58.3
1.83.1
datasaker/dsk-node-agent:latest1b95913b6729
google.golang.org/grpc@v1.58.3
1.83.1
datasaker/dsk-process-agent:latest2f38720a637d
google.golang.org/grpc@v1.58.3
1.83.1

Open the chart page →

7,606
ambassador-agentdatawire1.0.221 of 1See more

ambassador-agent datawire 1.0.22

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ambassador/ambassador-agent:1.0.227a1ea0d934fb
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

964
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
google.golang.org/grpc@v1.24.0
1.83.1

Open the chart page →

7,494
eg-edge-stackdatawire0.0.13 of 7See more

eg-edge-stack datawire 0.0.1

3 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
google.golang.org/grpc@v1.56.2
1.83.1
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
google.golang.org/grpc@v1.56.2
1.83.1
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/grpc@v1.56.2
1.83.1

Open the chart page →

15,861
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
defactops/defactops-ui:1.0.16825cdf9ba706
google.golang.org/grpc@v1.62.1
1.83.1

Open the chart page →

4,538
csi-driver-smbdeimosfr-charts1.20.35 of 5See more

csi-driver-smb deimosfr-charts 1.20.3

5 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
google.golang.org/grpc@v1.79.3
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

3,005
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
google.golang.org/grpc@v1.45.0
1.83.1

Open the chart page →

2,241
k8s-cloudwatch-adapterdeliveryheroVerified publisher0.2.21 of 1See more

k8s-cloudwatch-adapter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
google.golang.org/grpc@v1.23.1
1.83.1

Open the chart page →

2,475
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
google.golang.org/grpc@v1.46.0
1.83.1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
google.golang.org/grpc@v1.46.0
1.83.1

Open the chart page →

4,735
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

9,685
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/grpc@v1.15.0
1.83.1
quay.io/dexidp/dex:v2.25.07bcf286807b8
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

10,484
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

13,011
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

1,587
caddy-reverse-proxydevtron0.10.11 of 1See more

caddy-reverse-proxy devtron 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/caddy:latest13ba145cba2f
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

853
devtron-enterprisedevtron48.0.014 of 28See more

devtron-enterprise devtron 48.0.0

14 of the 28 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.83.1
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.83.1
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.83.1
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.83.1
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

68,695
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/grpc@v1.33.1
1.83.1
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

5,055
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/grpc@v1.20.1
1.83.1

Open the chart page →

11,959
kube-prometheus-stackdevtron19.3.02 of 6See more

kube-prometheus-stack devtron 19.3.0

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/grpc@v1.40.0
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

8,659
migrantdevtron0.0.31 of 1See more

migrant devtron 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
migrate/migrate:latest76cc2074cb66
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

112
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

2,441
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

1,514
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

9,685
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/grpc@v1.15.0
1.83.1
quay.io/dexidp/dex:v2.25.07bcf286807b8
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

10,484
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

13,011
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

1,587
caddy-reverse-proxydevtron-labs0.10.11 of 1See more

caddy-reverse-proxy devtron-labs 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/caddy:latestdf7f1c2fb114
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

853
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

10,094
devtron-enterprisedevtron-labs48.0.014 of 28See more

devtron-enterprise devtron-labs 48.0.0

14 of the 28 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.83.1
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.83.1
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.83.1
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.83.1
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

68,695
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/grpc@v1.33.1
1.83.1
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

5,055
devtron-operatordevtron-labs0.23.37 of 11See more

devtron-operator devtron-labs 0.23.3

7 of the 11 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.83.1
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.83.1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.83.1
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.83.1

Open the chart page →

33,180
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/grpc@v1.20.1
1.83.1

Open the chart page →

11,959
kube-prometheus-stackdevtron-labs19.3.02 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/grpc@v1.40.0
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

8,659
migrantdevtron-labs0.0.31 of 1See more

migrant devtron-labs 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
migrate/migrate:latestcc4ad8e19d66
google.golang.org/grpc@v1.74.2
1.83.1

Open the chart page →

740
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

2,441
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

1,514
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
langgenius/dify-plugin-daemon:main-localda995c129e2f
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

19,399
direktivdirektivVerified publisher0.10.01 of 6See more

direktiv direktiv 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
google.golang.org/grpc@v1.70.0
1.83.1

Open the chart page →

3,480
ownclouddjjudas21Verified publisher0.3.231 of 3See more

owncloud djjudas21 0.3.23

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
owncloud/server:10.16.3b3f9efdcd7f7
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

10,144
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
google.golang.org/grpc@v1.60.0
1.83.1

Open the chart page →

4,224
dnation-kubernetes-monitoring-stackdnationcloud4.0.28 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

8 of the 17 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
google.golang.org/grpc@v1.63.2
1.83.1
grafana/grafana:13.1.0121a7a9ece6d
google.golang.org/grpc@v1.79.3
1.83.1
grafana/loki:3.2.0882e30c20683
google.golang.org/grpc@v1.65.0
1.83.1
grafana/loki-canary:3.2.049e03f80d361
google.golang.org/grpc@v1.65.0
1.83.1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
google.golang.org/grpc@v1.50.1
1.83.1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
google.golang.org/grpc@v1.50.1
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

21,744
docker-authdocker-auth1.14.01 of 1See more

docker-auth docker-auth 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.14.098e0307e0d2d
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

1,514
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

8,417
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
google.golang.org/grpc@v1.32.0
1.83.1

Open the chart page →

3,055
corednsdoubanVerified publisher1.39.21 of 1See more

coredns douban 1.39.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
coredns/coredns:1.12.040384aa1f5ea
google.golang.org/grpc@v1.68.0
1.83.1

Open the chart page →

1,139
gatekeeperdoubanVerified publisher3.17.11 of 3See more

gatekeeper douban 3.17.1

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.17.1b7b4d7cfdd52
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

2,499
goinceptiondoubanVerified publisher0.3.11 of 2See more

goinception douban 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

1,208
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
google.golang.org/grpc@v1.55.0
1.83.1

Open the chart page →

3,668
service-proberdoubanVerified publisher0.1.01 of 1See more

service-prober douban 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

600
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
google.golang.org/grpc@v1.45.0
1.83.1

Open the chart page →

30,753

Container images carrying it

2,765 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/grafana:12.0.2b5b59bfc7561
google.golang.org/grpc@v1.72.1
1.83.1
1
grafana/grafana:12.3.2ba93c9d192e5
google.golang.org/grpc@v1.77.0
1.83.1
1
grafana/grafana:6.5.1befcd84da2c1
google.golang.org/grpc@v1.23.1
1.83.1
1
grafana/grafana:8.3.5cd7cb4345aa7
google.golang.org/grpc@v1.41.0
1.83.1
1
grafana/grafana:8.3.4cf81d2c753c8
google.golang.org/grpc@v1.41.0
1.83.1
1
grafana/grafana:7.4.5d322192ed2fa
google.golang.org/grpc@v1.35.0
1.83.1
1
grafana/grafana:8.5.3ecc1b80b8ca2
google.golang.org/grpc@v1.42.0
1.83.1
1
grafana/grafana:10.4.0f9811e4e687f
google.golang.org/grpc@v1.60.1
1.83.1
1
grafana/grafana:11.3.1fa801ab6e1ae
google.golang.org/grpc@v1.66.0
1.83.1
1
grafana/logcli:main-c90366d-amd643d85bb66e39b
google.golang.org/grpc@v1.37.0
1.83.1
1
grafana/loki:2.9.1035b02acc6765
google.golang.org/grpc@v1.56.3
1.83.1
1
grafana/loki:2.9.26074e01dbe03
google.golang.org/grpc@v1.56.3
1.83.1
1
grafana/loki:2.9.66ca6e2cd3b6f
google.golang.org/grpc@v1.56.3
1.83.1
1
grafana/loki:3.0.0757b5fadf816
google.golang.org/grpc@v1.62.1
1.83.1
1
grafana/loki:2.0.077e138f81a8e
google.golang.org/grpc@v1.29.1
1.83.1
1
grafana/loki:3.6.5847c287ada0e
google.golang.org/grpc@v1.75.1
1.83.1
1
grafana/loki:3.7.487f0a0676737
google.golang.org/grpc@v1.81.1
1.83.1
1
grafana/loki:3.2.0882e30c20683
google.golang.org/grpc@v1.65.0
1.83.1
1
grafana/loki:3.3.28af2de1abbdd
google.golang.org/grpc@v1.67.1
1.83.1
1
grafana/loki:3.6.192bd5700577b
google.golang.org/grpc@v1.75.1
1.83.1
1
grafana/loki:2.8.2b1da1d23037e
google.golang.org/grpc@v1.52.3
1.83.1
1
grafana/loki:2.4.2b3af8ead67d7
google.golang.org/grpc@v1.40.0
1.83.1
1
grafana/loki:3.6.3cd6e176883a9
google.golang.org/grpc@v1.75.1
1.83.1
1
grafana/loki:3.7.6efd47c67f9ba
google.golang.org/grpc@v1.82.1
1.83.1
1
grafana/loki-canary:3.0.028d7c00588aa
google.golang.org/grpc@v1.62.1
1.83.1
1
grafana/loki-canary:3.1.039baf6d67f85
google.golang.org/grpc@v1.62.1
1.83.1
1
grafana/loki-canary:2.9.24249db29b992
google.golang.org/grpc@v1.56.3
1.83.1
1
grafana/loki-canary:3.2.049e03f80d361
google.golang.org/grpc@v1.65.0
1.83.1
1
grafana/loki-canary:2.9.6549a40203e97
google.golang.org/grpc@v1.56.3
1.83.1
1
grafana/loki-canary:2.6.1ab2a2569307b
google.golang.org/grpc@v1.44.0
1.83.1
1
grafana/loki-canary:3.6.5fbb984bab741
google.golang.org/grpc@v1.75.1
1.83.1
1
grafana/mcp-grafana:0.14.042f541f22063
google.golang.org/grpc@v1.80.0
1.83.1
1
grafana/mcp-grafana:1.4.2f87fa67a561f
google.golang.org/grpc@v1.80.0
1.83.1
1
grafana/mimir:r292-5f018727476e456c738
google.golang.org/grpc@v1.63.2
1.83.1
1
grafana/mimir:2.0.080c1a8eb24dd
google.golang.org/grpc@v1.41.1
1.83.1
1
grafana/mimir:2.15.085f55510e0d3
google.golang.org/grpc@v1.65.0
1.83.1
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
google.golang.org/grpc@v1.75.0
1.83.1
1
grafana/phlare:0.5.1330f990cdad9
google.golang.org/grpc@v1.44.0
1.83.1
1
grafana/promtail:2.6.1072527b12cdf
google.golang.org/grpc@v1.44.0
1.83.1
1
grafana/promtail:2.0.05fd12edcc694
google.golang.org/grpc@v1.29.1
1.83.1
1
grafana/promtail:2.9.1063a2e57a5b14
google.golang.org/grpc@v1.56.3
1.83.1
1
grafana/promtail:3.5.165bfae480b57
google.golang.org/grpc@v1.71.0
1.83.1
1
grafana/promtail:3.6.18dcfdf466da0
google.golang.org/grpc@v1.75.1
1.83.1
1
grafana/promtail:2.7.0c16c710f7333
google.golang.org/grpc@v1.45.0
1.83.1
1
grafana/promtail:3.0.0d3de3da9431c
google.golang.org/grpc@v1.62.1
1.83.1
1
grafana/pyroscope:1.10.0319bf32ae06b
google.golang.org/grpc@v1.62.1
1.83.1
1
grafana/pyroscope:2.2.170cf34fcb09d
google.golang.org/grpc@v1.82.1
1.83.1
1
grafana/pyroscope:2.0.3cfd00e7f73c2
google.golang.org/grpc@v1.80.0
1.83.1
1
grafana/rollout-operator:v0.38.132fe838b79dd
google.golang.org/grpc@v1.82.0
1.83.1
1
grafana/rollout-operator:v0.14.03409edfb45c7
google.golang.org/grpc@v1.59.0
1.83.1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.