StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,309
of 17,821 indexed, latest versions
Container images
2,767
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,309 of 17,821 indexed charts deploy, on 2,767 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,763
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,309 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

9,743
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,528
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,077

Container images carrying it

2,767 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
netbirdio/netbird-server:0.78.2ac6317722f6f
google.golang.org/grpc@v1.80.0
1.83.1
1
netbirdio/relay:latest0ef3133050c7
google.golang.org/grpc@v1.80.0
1.83.1
1
netbirdio/relay:0.45.1872e3add0e1e
google.golang.org/grpc@v1.64.1
1.83.1
1
netbirdio/relay:0.60.2a10762533793
google.golang.org/grpc@v1.73.0
1.83.1
1
netbirdio/relay:0.46.0d32f82514a24
google.golang.org/grpc@v1.64.1
1.83.1
1
netbirdio/reverse-proxy:0.72.43104d5ca3a76
google.golang.org/grpc@v1.80.0
1.83.1
1
netbirdio/signal:latest04c401eb167e
google.golang.org/grpc@v1.80.0
1.83.1
1
netbirdio/signal:0.45.146ce5a45538f
google.golang.org/grpc@v1.64.1
1.83.1
1
netbirdio/signal:0.60.267176bcbf6ab
google.golang.org/grpc@v1.73.0
1.83.1
1
netbirdio/signal:0.46.0e8f392611152
google.golang.org/grpc@v1.64.1
1.83.1
1
netdata/netdata:v2.11.121970e176031
google.golang.org/grpc@v1.83.0
1.83.1
1
netrisai/bare-metal-dpu-agent:4.7.0.003c271efe749d0
google.golang.org/grpc@v1.65.1
1.83.1
1
netrisai/controller-grpc:4.6.0.00753178bf173c2
google.golang.org/grpc@v1.56.3
1.83.1
1
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
google.golang.org/grpc@v1.68.1
1.83.1
1
nginx/nginx-ingress:1.11.1eb5b4fd73325
google.golang.org/grpc@v1.27.1
1.83.1
1
ngosang/restic-exporter:2.1.2a8f9cfa30162
google.golang.org/grpc@v1.81.1
1.83.1
1
nocodb/nocodb:0.258.06779a4ddedf2
google.golang.org/grpc@v1.60.1
1.83.1
1
nocodb/nocodb:0.100.2b0b91ec2a2dd
google.golang.org/grpc@v1.48.0
1.83.1
1
nocodb/nocodb:0.84.15f9b799933aa8
google.golang.org/grpc@v1.40.1
1.83.1
1
novosga/novosga:latest34b9acbe6e51
google.golang.org/grpc@v1.80.0
1.83.1
1
nutanix/cn-rwx-operator:1.1.00082e0cebd42
google.golang.org/grpc@v1.79.3
1.83.1
1
nvidia/dcgm-exporter:2.2.9-2.4.1-ubuntu20.0491b20b66d1cd
google.golang.org/grpc@v1.35.0
1.83.1
1
oamdev/cluster-gateway:v1.9.0-alpha.25591e29d66a2
google.golang.org/grpc@v1.49.0
1.83.1
1
oamdev/cluster-gateway:v1.4.0dc97164c4c1f
google.golang.org/grpc@v1.42.0
1.83.1
1
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
google.golang.org/grpc@v1.42.0
1.83.1
1
oamdev/terraform-controller:v0.8.070447f4d360a
google.golang.org/grpc@v1.27.1
1.83.1
1
oamdev/vela-core:v1.11.095fa412c934e
google.golang.org/grpc@v1.67.1
1.83.1
1
oamdev/vela-prism:v1.6.06db6a937647d
google.golang.org/grpc@v1.42.0
1.83.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
google.golang.org/grpc@v1.75.0
1.83.1
1
ofekmeister/csi-gcs:v0.9.030d70fa9211b
google.golang.org/grpc@v1.44.0
1.83.1
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
google.golang.org/grpc@v1.64.1
1.83.1
1
okteto/civo-webhook:0.5.357cd51176538
google.golang.org/grpc@v1.57.0
1.83.1
1
onkar17/grafana:latestaef3ebd6e24e
google.golang.org/grpc@v1.36.0
1.83.1
1
opencloudeu/opencloud:7.2.46d992ccc5f1c
google.golang.org/grpc@v1.81.1
1.83.1
1
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
google.golang.org/grpc@v1.27.1
1.83.1
1
opencsghq/csghub-server:v2.5.0-ee587046575c2c
google.golang.org/grpc@v1.82.1
1.83.1
1
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
google.golang.org/grpc@v1.71.0
1.83.1
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
google.golang.org/grpc@v1.67.1
1.83.1
1
opencsghq/gitlab-shell:v19.2.580a65ac370da
google.golang.org/grpc@v1.80.0
1.83.1
1
opencsghq/kube-state-metrics:v2.19.15ea147562ec8
google.golang.org/grpc@v1.79.3
1.83.1
1
opencsghq/lws:v0.6.1de15437db41b
google.golang.org/grpc@v1.65.0
1.83.1
1
opencsghq/prometheus:v3.13.00aac0d04749e
google.golang.org/grpc@v1.81.1
1.83.1
1
openebs/lvm-driver:1.10.141f73aba7f31
google.golang.org/grpc@v1.79.3
1.83.1
1
openebs/provisioner-nfs:0.11.04f41dd782761
google.golang.org/grpc@v1.55.0
1.83.1
1
openebs/zfs-driver:2.11.116f1a74bb249
google.golang.org/grpc@v1.82.1
1.83.1
1
openfga/openfga:v1.18.036097b960f66
google.golang.org/grpc@v1.81.1
1.83.1
1
openfga/openfga:v1.9.25e94966c11df
google.golang.org/grpc@v1.73.0
1.83.1
1
openkruise/agent-sandbox-controller:v0.3.0e0a3bf7c0dc5
google.golang.org/grpc@v1.75.1
1.83.1
1
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
google.golang.org/grpc@v1.75.0
1.83.1
1
openkruise/kruise-manager:v1.8.30482722b4e56
google.golang.org/grpc@v1.63.0
1.83.1
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.