StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,309
of 17,821 indexed, latest versions
Container images
2,767
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,309 of 17,821 indexed charts deploy, on 2,767 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,763
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,309 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

9,743
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,528
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,077

Container images carrying it

2,767 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
google.golang.org/grpc@v1.52.0
1.83.1
1
hiversh/antigravity:0.1.45-microvm0e36d98402bc
google.golang.org/grpc@v1.80.0
1.83.1
1
hiversh/browser:0.1.45-microvmb5048c6342ce
google.golang.org/grpc@v1.80.0
1.83.1
1
hiversh/claude:0.1.45-microvm2fbf9f264498
google.golang.org/grpc@v1.80.0
1.83.1
1
hiversh/codex:0.1.45-microvm4f43130f51e5
google.golang.org/grpc@v1.80.0
1.83.1
1
hiversh/controller:0.1.45b0b85f8942c7
google.golang.org/grpc@v1.80.0
1.83.1
1
hiversh/copilot:0.1.45-microvm50c07b84f298
google.golang.org/grpc@v1.80.0
1.83.1
1
hiversh/node:0.1.45-alpine-microvm836a37641941
google.golang.org/grpc@v1.80.0
1.83.1
1
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
google.golang.org/grpc@v1.80.0
1.83.1
1
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
google.golang.org/grpc@v1.80.0
1.83.1
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
google.golang.org/grpc@v1.39.0
1.83.1
1
holoinsight/agent:latest5c3994e742f8
google.golang.org/grpc@v1.46.2
1.83.1
1
holoinsight/otelcontribcol:latest42ba8dc3113c
google.golang.org/grpc@v1.54.0
1.83.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
google.golang.org/grpc@v1.59.0
1.83.1
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
google.golang.org/grpc@v1.82.1
1.83.1
1
huacnlee/gobackup:v3.1.1560be93229a5
google.golang.org/grpc@v1.59.0
1.83.1
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
google.golang.org/grpc@v1.49.0
1.83.1
1
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
google.golang.org/grpc@v1.41.0
1.83.1
1
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
google.golang.org/grpc@v1.26.0
1.83.1
1
hyperledger/fabric-ca:1.5.0f270dfeee91d
google.golang.org/grpc@v1.26.0
1.83.1
1
hyperledger/fabric-orderer:2.2.137294e05209b
google.golang.org/grpc@v1.29.1
1.83.1
1
hyperledger/fabric-peer:2.2.1bf4995c86af6
google.golang.org/grpc@v1.29.1
1.83.1
1
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
google.golang.org/grpc@v1.53.0
1.83.1
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
google.golang.org/grpc@v1.53.0
1.83.1
1
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
google.golang.org/grpc@v1.29.1
1.83.1
1
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
google.golang.org/grpc@v1.50.1
1.83.1
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
google.golang.org/grpc@v1.52.3
1.83.1
1
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
google.golang.org/grpc@v1.51.0
1.83.1
1
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
google.golang.org/grpc@v1.51.0
1.83.1
1
inaccel/cloud-init:latesta5d3d0af05c1
google.golang.org/grpc@v1.60.1
1.83.1
1
inaccel/device-selector:latest44b4f274f40b
google.golang.org/grpc@v1.61.0
1.83.1
1
infisical/cli:0.43.1230941c1293b77
google.golang.org/grpc@v1.82.1
1.83.1
1
infisical/infisical-csi-provider:v0.0.9e3390e677db6
google.golang.org/grpc@v1.64.1
1.83.1
1
infisical/kubernetes-operator:v0.11.9769ad1630a13
google.golang.org/grpc@v1.79.3
1.83.1
1
infisical/pki-issuer:latestff38294270e3
google.golang.org/grpc@v1.79.3
1.83.1
1
inseefrlab/shelly:cloudshell31f04ca7436b
google.golang.org/grpc@v1.33.1
1.83.1
1
instill/api-gateway:9bfdc88b53eaa51c523
google.golang.org/grpc@v1.71.0
1.83.1
1
instill/artifact-backend:b28766ac4a393e601ed
google.golang.org/grpc@v1.61.0
1.83.1
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
google.golang.org/grpc@v1.73.0
1.83.1
1
instill/model-backend:611f0f2e980125e5ba5
google.golang.org/grpc@v1.73.0
1.83.1
1
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
google.golang.org/grpc@v1.65.0
1.83.1
1
intel/intel-gpu-plugin:0.20.0143f0a45e174
google.golang.org/grpc@v1.27.1
1.83.1
1
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
google.golang.org/grpc@v1.65.0
1.83.1
1
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
google.golang.org/grpc@v1.65.0
1.83.1
1
intel/multimodal-data-visualization:3.03426deb77337
google.golang.org/grpc@v1.45.0
1.83.1
1
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
google.golang.org/grpc@v1.41.0
1.83.1
1
iomesh/csi-driver:v2.8.01a151f602451
google.golang.org/grpc@v1.41.0
1.83.1
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.