StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,309
of 17,821 indexed, latest versions
Container images
2,767
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,309 of 17,821 indexed charts deploy, on 2,767 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,763
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,309 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

9,743
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,528
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,077

Container images carrying it

2,767 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kubeoperator/webkubectl:v2.4.0be8f0d624640
google.golang.org/grpc@v1.27.0
1.83.1
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
google.golang.org/grpc@v1.73.0
1.83.1
1
kubeshark/hub:v53.46d3f22525a0e
google.golang.org/grpc@v1.82.1
1.83.1
1
kubeshark/worker:v53.4b226490dfa11
google.golang.org/grpc@v1.82.1
1.83.1
1
kubeshop/kusk-gateway:v1.5.48b5bfd57a3ce
google.golang.org/grpc@v1.47.0
1.83.1
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
google.golang.org/grpc@v1.70.0
1.83.1
1
kubeshop/testkube-logs-server:latest094186b19698
google.golang.org/grpc@v1.70.0
1.83.1
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
google.golang.org/grpc@v1.79.3
1.83.1
1
kubeshop/testkube-operator:2.1.154def0d0f0d4ab
google.golang.org/grpc@v1.70.0
1.83.1
1
kubeshop/tracetest:v1.7.173d7e3a2db43
google.golang.org/grpc@v1.58.3
1.83.1
1
kubesphere/ks-extensions-museum:latest29681958f220
google.golang.org/grpc@v1.58.3
1.83.1
1
kubesphere/kubectl:v1.27.1649b445b1b732
google.golang.org/grpc@v1.58.3
1.83.1
1
kubesphere/openelb:v0.5.0b5b665c4672c
google.golang.org/grpc@v1.26.0
1.83.1
1
kubesphere/openelb:v0.4.4ed7311a0f9e4
google.golang.org/grpc@v1.26.0
1.83.1
1
kubesphere/porter:v0.4.38d1ed5ee1d2e
google.golang.org/grpc@v1.26.0
1.83.1
1
kubevious/ui:1.2.16233e84bdd59
google.golang.org/grpc@v1.46.0
1.83.1
1
kubevip/kube-vip-cloud-provider:v0.0.12f8f4e3401f76
google.golang.org/grpc@v1.65.0
1.83.1
1
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
google.golang.org/grpc@v1.78.0
1.83.1
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
google.golang.org/grpc@v1.49.0
1.83.1
1
kusionstack/karpor:v0.6.4b707d3bf0abd
google.golang.org/grpc@v1.51.0
1.83.1
1
kusionstack/kusion:v0.14.0126c8f0b0976
google.golang.org/grpc@v1.69.0
1.83.1
1
kvalitetsit/kitcaddy:1.5.110e66907ea266
google.golang.org/grpc@v1.81.0
1.83.1
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
google.golang.org/grpc@v1.37.0
1.83.1
1
kvalitetsit/myra-cert-manager-webhook:1.2.184ab59a1434e
google.golang.org/grpc@v1.81.1
1.83.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
google.golang.org/grpc@v1.82.1
1.83.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
google.golang.org/grpc@v1.81.1
1.83.1
1
langgenius/dify-ee-audit:3.9.8-ubi9e99aed151fc5
google.golang.org/grpc@v1.81.0
1.83.1
1
langgenius/dify-ee-collector:3.9.8-ubi9a9b91fd62c94
google.golang.org/grpc@v1.81.0
1.83.1
1
langgenius/dify-ee-enterprise:3.9.8-ubi9c392a36a4ef7
google.golang.org/grpc@v1.81.0
1.83.1
1
langgenius/dify-ee-gateway:3.9.8-ubi99e314c29a61f
google.golang.org/grpc@v1.81.0
1.83.1
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
google.golang.org/grpc@v1.81.0
1.83.1
1
langgenius/dify-ee-plugin-crd:3.9.8-ubi96f4e0e5f6e5a
google.golang.org/grpc@v1.81.0
1.83.1
1
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
google.golang.org/grpc@v1.80.0
1.83.1
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
google.golang.org/grpc@v1.81.0
1.83.1
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
google.golang.org/grpc@v1.80.0
1.83.1
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
google.golang.org/grpc@v1.72.0
1.83.1
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
google.golang.org/grpc@v1.82.1
1.83.1
1
launchdarkly/ld-relay:8.21.08fc1437962a9
google.golang.org/grpc@v1.82.1
1.83.1
1
lavr/express-botx:0.39.0-rootlessf5035e0f1434
google.golang.org/grpc@v1.65.0
1.83.1
1
layer5/meshery:stable-latest78a8be21bef3
google.golang.org/grpc@v1.72.0
1.83.1
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
google.golang.org/grpc@v1.47.0
1.83.1
1
layer5/meshery-consul:stable-latest25a4cc38abcd
google.golang.org/grpc@v1.58.3
1.83.1
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
google.golang.org/grpc@v1.29.1
1.83.1
1
layer5/meshery-istio:stable-latestfde47c141ec6
google.golang.org/grpc@v1.60.1
1.83.1
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
google.golang.org/grpc@v1.56.3
1.83.1
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
google.golang.org/grpc@v1.60.1
1.83.1
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
google.golang.org/grpc@v1.54.0
1.83.1
1
layer5/meshery-nsm:stable-latestebd6a8faf21f
google.golang.org/grpc@v1.34.0
1.83.1
1
layer5/meshery-osm:stable-latestec898e5786c6
google.golang.org/grpc@v1.52.0
1.83.1
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
google.golang.org/grpc@v1.54.0
1.83.1
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.