StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,232
of 17,803 indexed, latest versions
Container images
2,708
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,232 of 17,803 indexed charts deploy, on 2,708 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+114 more1.83.12,705
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed3
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,232 by stars
ChartLatestAffected imagesRadar Score
kube-state-metricswenerme8.5.01 of 1See more

kube-state-metrics wenerme 8.5.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

89
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

15,310
mesherywenerme1.0.701 of 1See more

meshery wenerme 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

1,445
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

6,922
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

6,145
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
google.golang.org/grpc@v1.47.0
1.83.1
openebs/provisioner-localpv:3.5.0aea39e49bb97
google.golang.org/grpc@v1.55.0
1.83.1

Open the chart page →

10,602
prometheuswenerme29.30.12See more

prometheus wenerme 29.30.1

2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

rancherwenerme2.15.12 of 2See more

rancher wenerme 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
google.golang.org/grpc@v1.79.3
1.83.1
rancher/shell:v0.8.1f293af9c635f
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,487
temporalwenerme0.15.14 of 13See more

temporal wenerme 0.15.1

4 of the 13 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
google.golang.org/grpc@v1.23.1
1.83.1
prom/prometheus:v2.16.0e4ca62c0d62f
google.golang.org/grpc@v1.22.1
1.83.1
temporalio/admin-tools:1.15.135034611d981
google.golang.org/grpc@v1.44.0
1.83.1
temporalio/server:1.15.1e26758f5a1bf
google.golang.org/grpc@v1.44.0
1.83.1

Open the chart page →

22,707
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

3,378
vaultwenerme0.34.11 of 2See more

vault wenerme 0.34.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/vault:2.0.45be49781ecf7
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

549
victoria-metrics-k8s-stackwenerme0.92.13 of 7See more

victoria-metrics-k8s-stack wenerme 0.92.1

3 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:13.1.17cb8c64c4d57
google.golang.org/grpc@v1.81.1
1.83.1
victoriametrics/operator:v0.74.17310c4a80b94
google.golang.org/grpc@v1.82.1
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,915
victoria-metrics-operatorwenerme0.67.31 of 1See more

victoria-metrics-operator wenerme 0.67.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
victoriametrics/operator:v0.74.17310c4a80b94
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

115
wexa-studiowexa-studio1.2.05 of 15See more

wexa-studio wexa-studio 1.2.0

5 of the 15 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
google.golang.org/grpc@v1.58.3
1.83.1
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
google.golang.org/grpc@v1.60.1
1.83.1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
google.golang.org/grpc@v1.56.3
1.83.1
temporalio/server:1.29.1c1e3326b2ce1
google.golang.org/grpc@v1.72.2
1.83.1
temporalio/ui:2.44.00b36e00aad30
google.golang.org/grpc@v1.66.1
1.83.1

Open the chart page →

15,056
ceph-csi-cephfswikimedia0.1.85 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

5 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/csi-provisioner:v3.2.14ad5fcdbe7e9
google.golang.org/grpc@v1.45.0
1.83.1
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
google.golang.org/grpc@v1.48.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
google.golang.org/grpc@v1.40.0
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
google.golang.org/grpc@v1.40.0
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

10,321
ceph-csi-rbdwikimedia0.1.136 of 6See more

ceph-csi-rbd wikimedia 0.1.13

6 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/csi-provisioner:v3.2.14ad5fcdbe7e9
google.golang.org/grpc@v1.45.0
1.83.1
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
google.golang.org/grpc@v1.48.0
1.83.1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
google.golang.org/grpc@v1.40.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
google.golang.org/grpc@v1.40.0
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
google.golang.org/grpc@v1.40.0
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

11,827
jaegerwikimedia3.1.23 of 4See more

jaeger wikimedia 3.1.2

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
google.golang.org/grpc@v1.60.0
1.83.1
jaegertracing/jaeger-collector:1.53.07f1269222903
google.golang.org/grpc@v1.60.0
1.83.1
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
google.golang.org/grpc@v1.60.0
1.83.1

Open the chart page →

9,340
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
google.golang.org/grpc@v1.56.1
1.83.1

Open the chart page →

2,032
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
google.golang.org/grpc@v1.30.0
1.83.1

Open the chart page →

2,752
csi-driver-host-pathwiremindVerified publisher0.1.18 of 8See more

csi-driver-host-path wiremind 0.1.1

8 of the 8 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
google.golang.org/grpc@v1.47.0
1.83.1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
google.golang.org/grpc@v1.48.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
google.golang.org/grpc@v1.50.1
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
google.golang.org/grpc@v1.49.0
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
google.golang.org/grpc@v1.47.0
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
google.golang.org/grpc@v1.47.0
1.83.1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
google.golang.org/grpc@v1.34.0
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
google.golang.org/grpc@v1.48.0
1.83.1

Open the chart page →

12,663
orcwiremindVerified publisher0.3.01 of 1See more

orc wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/orc/openstack-resource-controller:v2.5.079f22af49612
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

269
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
google.golang.org/grpc@v1.68.0
1.83.1

Open the chart page →

1,195
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

2,512
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

2,623
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

1,042
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

13,813
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

394
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,401
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,965
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,000
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

899
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,047

Container images carrying it

2,708 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
google.golang.org/grpc@v1.53.0
1.83.1
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
google.golang.org/grpc@v1.53.0
1.83.1
1
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
google.golang.org/grpc@v1.29.1
1.83.1
1
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
google.golang.org/grpc@v1.50.1
1.83.1
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
google.golang.org/grpc@v1.52.3
1.83.1
1
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
google.golang.org/grpc@v1.51.0
1.83.1
1
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
google.golang.org/grpc@v1.51.0
1.83.1
1
inaccel/cloud-init:latesta5d3d0af05c1
google.golang.org/grpc@v1.60.1
1.83.1
1
inaccel/device-selector:latest44b4f274f40b
google.golang.org/grpc@v1.61.0
1.83.1
1
infisical/cli:0.43.1230941c1293b77
google.golang.org/grpc@v1.82.1
1.83.1
1
infisical/infisical-csi-provider:v0.0.9e3390e677db6
google.golang.org/grpc@v1.64.1
1.83.1
1
infisical/kubernetes-operator:v0.11.9769ad1630a13
google.golang.org/grpc@v1.79.3
1.83.1
1
infisical/pki-issuer:latestff38294270e3
google.golang.org/grpc@v1.79.3
1.83.1
1
inseefrlab/shelly:cloudshell31f04ca7436b
google.golang.org/grpc@v1.33.1
1.83.1
1
instill/api-gateway:9bfdc88b53eaa51c523
google.golang.org/grpc@v1.71.0
1.83.1
1
instill/artifact-backend:b28766ac4a393e601ed
google.golang.org/grpc@v1.61.0
1.83.1
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
google.golang.org/grpc@v1.73.0
1.83.1
1
instill/model-backend:611f0f2e980125e5ba5
google.golang.org/grpc@v1.73.0
1.83.1
1
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
google.golang.org/grpc@v1.65.0
1.83.1
1
intel/intel-gpu-plugin:0.20.0143f0a45e174
google.golang.org/grpc@v1.27.1
1.83.1
1
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
google.golang.org/grpc@v1.65.0
1.83.1
1
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
google.golang.org/grpc@v1.65.0
1.83.1
1
intel/multimodal-data-visualization:3.03426deb77337
google.golang.org/grpc@v1.45.0
1.83.1
1
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/csi-driver:v2.8.01a151f602451
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/csi-driver:v2.7.25d3f9bf9240b
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/deck:v0.2.0282d6c419ed3
google.golang.org/grpc@v1.60.0
1.83.1
1
iomesh/deck:v0.1.0a31e26b6ae22
google.golang.org/grpc@v1.60.0
1.83.1
1
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
google.golang.org/grpc@v1.60.0
1.83.1
1
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
google.golang.org/grpc@v1.60.0
1.83.1
1
iomesh/node-disk-manager:1.8.0002c4b92fd34
google.golang.org/grpc@v1.27.1
1.83.1
1
iomesh/node-disk-manager:1.8.0-2292ad270082e
google.golang.org/grpc@v1.27.1
1.83.1
1
iomesh/operator:v1.1.060081c9b2f52
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/operator:v1.2.0ba4dd6be7e59
google.golang.org/grpc@v1.41.0
1.83.1
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
google.golang.org/grpc@v1.29.1
1.83.1
1
iotaledger/goshimmer:v0.8.6b02a8f77474f
google.golang.org/grpc@v1.40.0
1.83.1
1
iotaledger/hornet:2.001206f1ba89c
google.golang.org/grpc@v1.57.0
1.83.1
1
iotaledger/inx-dashboard:1.012c669cb8748
google.golang.org/grpc@v1.57.0
1.83.1
1
ipfs/go-ipfs:v0.13.117259397f587
google.golang.org/grpc@v1.46.0
1.83.1
1
ipfs/ipfs-cluster:1.0.21511f6d57994
google.golang.org/grpc@v1.45.0
1.83.1
1
ipfs/kubo:v0.41.00661819c2e09
google.golang.org/grpc@v1.79.3
1.83.1
1
ipfs/kubo:latest63f5502f7a01
google.golang.org/grpc@v1.81.1
1.83.1
1
ipfs/kubo:v0.17.0803fac58ba15
google.golang.org/grpc@v1.47.0
1.83.1
1
ipfs/kubo:v0.24.0e3de33bd746b
google.golang.org/grpc@v1.55.0
1.83.1
1
ispras/svacer:11-2-042aa9fa9f189
google.golang.org/grpc@v1.72.0
1.83.1
1
istio/install-cni:1.10.32232f365aed6
google.golang.org/grpc@v1.36.0
1.83.1
1
istio/install-cni:1.23.6ab34c4740f44
google.golang.org/grpc@v1.65.0
1.83.1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.