StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,309
of 17,821 indexed, latest versions
Container images
2,767
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,309 of 17,821 indexed charts deploy, on 2,767 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,763
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,309 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

9,743
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,528
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,077

Container images carrying it

2,767 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
jamesread/olivetin:3000.19.0af9d7c4db6dc
google.golang.org/grpc@v1.82.1
1.83.1
1
jhonbrownn/elchi-backend:v1.6.14-v0.14.0-envoy1.39.031aee9ba2c63
google.golang.org/grpc@v1.82.1
1.83.1
1
jhonbrownn/elchi-collector:v0.1.119fdd0724865e
google.golang.org/grpc@v1.80.0
1.83.1
1
jkremser/log2rbac:v0.0.5e35cf56ef183
google.golang.org/grpc@v1.45.0
1.83.1
1
jmferrer/azure-devops-agent:latest030f68ec6998
google.golang.org/grpc@v1.24.0
1.83.1
1
johnblack77/clustereye-api:latest16c25fd2128c
google.golang.org/grpc@v1.71.0
1.83.1
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
google.golang.org/grpc@v1.56.3
1.83.1
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
google.golang.org/grpc@v1.48.0
1.83.1
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
google.golang.org/grpc@v1.48.0
1.83.1
1
junktext/getting-started:1.0.5a70936c04aed
google.golang.org/grpc@v1.54.0
1.83.1
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
google.golang.org/grpc@v1.40.0
1.83.1
1
kazem26/liqo-upgrade-operator:v0.1268b7c6a59dd
google.golang.org/grpc@v1.72.1
1.83.1
1
keelhq/keel:0.19.202ac4ea616c4
google.golang.org/grpc@v1.54.0
1.83.1
1
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
google.golang.org/grpc@v1.72.1
1.83.1
1
keptncontrib/prometheus-service:0.6.029969dd547de
google.golang.org/grpc@v1.27.1
1.83.1
1
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
google.golang.org/grpc@v1.20.0
1.83.1
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
google.golang.org/grpc@v1.53.0
1.83.1
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
google.golang.org/grpc@v1.31.1
1.83.1
1
kiosksh/kiosk:0.2.11501725ba2025
google.golang.org/grpc@v1.27.1
1.83.1
1
komodorio/helm-dashboard:2.1.3258a9044e658
google.golang.org/grpc@v1.82.1
1.83.1
1
kong/gateway-operator:1.603510967482b
google.golang.org/grpc@v1.71.1
1.83.1
1
kserve/kserve-controller:v0.10.022ff858b57c1
google.golang.org/grpc@v1.48.0
1.83.1
1
kserve/kserve-controller:v0.8.0f0692a9ea09f
google.golang.org/grpc@v1.42.0
1.83.1
1
kubearmor/kubearmor:stablea08141311045
google.golang.org/grpc@v1.81.1
1.83.1
1
kubearmor/kubearmor-controller:latestf40f745222b9
google.golang.org/grpc@v1.82.1
1.83.1
1
kubearmor/kubearmor-operator:v1.7.43faab85da688
google.golang.org/grpc@v1.81.1
1.83.1
1
kubearmor/kubearmor-relay-server:latest2dd4809d7c11
google.golang.org/grpc@v1.80.0
1.83.1
1
kubebb/cert-manager-controller:v1.8.020509de4b399
google.golang.org/grpc@v1.43.0
1.83.1
1
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
google.golang.org/grpc@v1.43.0
1.83.1
1
kubebb/core:v0.1.62b9e7f451d6b
google.golang.org/grpc@v1.50.1
1.83.1
1
kubebb/core:lateste366c34a9b8d
google.golang.org/grpc@v1.57.1
1.83.1
1
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
google.golang.org/grpc@v1.38.0
1.83.1
1
kubebb/mesh-operator:v5.7.0163ebbfc7a82
google.golang.org/grpc@v1.50.1
1.83.1
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
google.golang.org/grpc@v1.45.0
1.83.1
1
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
google.golang.org/grpc@v1.58.3
1.83.1
1
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
google.golang.org/grpc@v1.27.1
1.83.1
1
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
google.golang.org/grpc@v1.27.1
1.83.1
1
kubedb/operator:v0.24.01a06ff0bda52
google.golang.org/grpc@v1.27.1
1.83.1
1
kubeedge/edgemesh-agent:latest460c6061b608
google.golang.org/grpc@v1.42.0
1.83.1
1
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
google.golang.org/grpc@v1.32.0
1.83.1
1
kubeflowkatib/katib-controller:v0.17.072f14e03b9e1
google.golang.org/grpc@v1.58.3
1.83.1
1
kubeflowkatib/katib-db-manager:v0.17.0916a7695b0dd
google.golang.org/grpc@v1.58.3
1.83.1
1
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
google.golang.org/grpc@v1.32.0
1.83.1
1
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
google.golang.org/grpc@v1.32.0
1.83.1
1
kubeflowkatib/katib-ui:v0.17.07a41c508deb1
google.golang.org/grpc@v1.58.3
1.83.1
1
kubeflow/model-registry:v0.2.95783f6db428f
google.golang.org/grpc@v1.67.1
1.83.1
1
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
google.golang.org/grpc@v1.42.0
1.83.1
1
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
google.golang.org/grpc@v1.42.0
1.83.1
1
kubegems/kube-rbac-proxy:v0.8.0941f557ed1ee
google.golang.org/grpc@v1.27.0
1.83.1
1
kubegreen/kube-green:0.7.12dc0f0a6034c
google.golang.org/grpc@v1.68.1
1.83.1
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.