StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,309
of 17,821 indexed, latest versions
Container images
2,767
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,309 of 17,821 indexed charts deploy, on 2,767 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,763
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,309 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

9,743
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,528
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,077

Container images carrying it

2,767 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mattermost/rtcd:latesta27058aaa53a
google.golang.org/grpc@v1.70.0
1.83.1
1
mavrick1/kubestellar-b:latest45ca0429a1d4
google.golang.org/grpc@v1.53.0
1.83.1
1
mcp/kubernetes:latest5ffbf7f0a8aa
google.golang.org/grpc@v1.80.0
1.83.1
1
megaease/easegress:latestfad1c7452958
google.golang.org/grpc@v1.71.1
1.83.1
1
meshery/meshery-operator:1.0.50d245bc8b5c6
google.golang.org/grpc@v1.82.1
1.83.1
1
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
google.golang.org/grpc@v1.56.1
1.83.1
1
mesosphere/dex-controller:v0.16.11b2dd9c0b0fc
google.golang.org/grpc@v1.61.0
1.83.1
1
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
google.golang.org/grpc@v1.26.0
1.83.1
1
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
google.golang.org/grpc@v1.26.0
1.83.1
1
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
google.golang.org/grpc@v1.26.0
1.83.1
1
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
google.golang.org/grpc@v1.26.0
1.83.1
1
mesosphere/kubefed:proxyurl4fd8889195fe
google.golang.org/grpc@v1.27.0
1.83.1
1
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
google.golang.org/grpc@v1.66.2
1.83.1
1
milvusdb/etcd:3.5.5-r2102aac62827b
google.golang.org/grpc@v1.41.0
1.83.1
1
milvusdb/etcd:3.5.25-r1fededb2f2d63
google.golang.org/grpc@v1.71.1
1.83.1
1
milvusdb/milvus:v2.2.13a3a55e1c1497
google.golang.org/grpc@v1.48.0
1.83.1
1
milvusdb/milvus-operator:v1.3.95d63c8894f3a
google.golang.org/grpc@v1.82.1
1.83.1
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
google.golang.org/grpc@v1.26.0
1.83.1
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
google.golang.org/grpc@v1.43.0
1.83.1
1
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
google.golang.org/grpc@v1.22.0
1.83.1
1
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
google.golang.org/grpc@v1.26.0
1.83.1
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
google.golang.org/grpc@v1.41.0
1.83.1
1
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
google.golang.org/grpc@v1.64.0
1.83.1
1
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
google.golang.org/grpc@v1.60.1
1.83.1
1
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
google.golang.org/grpc@v1.26.0
1.83.1
1
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
google.golang.org/grpc@v1.22.0
1.83.1
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
google.golang.org/grpc@v1.51.0
1.83.1
1
minio/operator:v5.0.9170b154d2c61
google.golang.org/grpc@v1.53.0
1.83.1
1
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
google.golang.org/grpc@v1.19.0
1.83.1
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
google.golang.org/grpc@v1.24.0
1.83.1
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
google.golang.org/grpc@v1.24.0
1.83.1
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
google.golang.org/grpc@v1.24.0
1.83.1
1
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
google.golang.org/grpc@v1.24.0
1.83.1
1
moby/buildkit:v0.31.0a095b3d11ce1
google.golang.org/grpc@v1.81.1
1.83.1
1
moby/buildkit:v0.10.0c2aeafaed434
google.golang.org/grpc@v1.44.0
1.83.1
1
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.83.1
1
neosmemo/memos:0.293e1253477066
google.golang.org/grpc@v1.80.0
1.83.1
1
neosmemo/memos:0.26.23eefcc231141
google.golang.org/grpc@v1.75.1
1.83.1
1
neosmemo/memos:0.24c6defc2dfb98
google.golang.org/grpc@v1.72.2
1.83.1
1
nerzhul/mc-arm64:2020.10.034215df511f31
google.golang.org/grpc@v1.26.0
1.83.1
1
netapp/controller:25.11.0-bxp-preview06f6c9a0653f
google.golang.org/grpc@v1.72.1
1.83.1
1
netapp/controller:26.08.0-console09c6cc6b5f71
google.golang.org/grpc@v1.80.0
1.83.1
1
netapp/controller:26.06.08235a77cfc92
google.golang.org/grpc@v1.80.0
1.83.1
1
netapp/trident-operator:21.10.049cfe552d9c2
google.golang.org/grpc@v1.41.0
1.83.1
1
netapp/trident-operator:26.06.15e8ba78f4ab1
google.golang.org/grpc@v1.83.0
1.83.1
1
netbirdio/management:0.45.10c9994b393ea
google.golang.org/grpc@v1.64.1
1.83.1
1
netbirdio/management:latest3c3bed2a982c
google.golang.org/grpc@v1.80.0
1.83.1
1
netbirdio/management:0.60.252682e5f48f9
google.golang.org/grpc@v1.73.0
1.83.1
1
netbirdio/management:0.46.0b0adc4ad4ec6
google.golang.org/grpc@v1.64.1
1.83.1
1
netbirdio/netbird-server:0.78.13086534361a1
google.golang.org/grpc@v1.80.0
1.83.1
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.