StackRadar

CVE-2026-84303

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,270
of 17,790 indexed, latest versions
Container images
2,748
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,270 of 17,790 indexed charts deploy, on 2,748 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+114 more1.83.12,745
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed3
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Trending
Rank 41 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,270 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackprometheus-communityOfficialVerified publisher91.4.11See more

kube-prometheus-stack prometheus-community 91.4.1

1 container image this version deploys carries CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

argo-cdargoOfficialVerified publisher10.9.12 of 3See more

argo-cd argo 10.9.1

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
google.golang.org/grpc@v1.79.1
1.83.1
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

2,989
prometheusprometheus-communityOfficialVerified publisher29.30.03 of 6See more

prometheus prometheus-community 29.30.0

3 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

458
metrics-servermetrics-serverVerified publisher3.14.01 of 1See more

metrics-server metrics-server 3.14.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.9.0d9862115e7c7
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

156
vaulthashicorpVerified publisher0.34.11 of 2See more

vault hashicorp 0.34.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/vault:2.0.45be49781ecf7
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

543
harborharborOfficialVerified publisher1.19.25 of 8See more

harbor harbor 1.19.2

5 of the 8 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.15.2d7b780d23721
google.golang.org/grpc@v1.81.1
1.83.1
goharbor/harbor-jobservice:v2.15.2f71a4452a095
google.golang.org/grpc@v1.81.1
1.83.1
goharbor/harbor-registryctl:v2.15.2223d5cb49d5d
google.golang.org/grpc@v0.0.0-20160317175043-d3ddb4469d5a
1.83.1
goharbor/registry-photon:v2.15.2c4ebef61ceb5
google.golang.org/grpc@v0.0.0-20160317175043-d3ddb4469d5a
1.83.1
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

1,650
external-secretsexternal-secrets-operatorVerified publisher2.10.01 of 1See more

external-secrets external-secrets-operator 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v2.10.0814117b0fd6d
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

77
longhornlonghorn1.12.12 of 3See more

longhorn longhorn 1.12.1

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.12.183b79f57043f
google.golang.org/grpc@v1.83.0
1.83.1
longhornio/longhorn-share-manager:v1.12.1efaf47aeb4e8
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

555
velerovmware-tanzu12.1.01 of 1See more

velero vmware-tanzu 12.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
velero/velero:v1.18.111459094b1b2
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

1,337
metallbmetallbVerified publisher0.16.13 of 4See more

metallb metallb 0.16.1

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.16.1f51ab515de9c
google.golang.org/grpc@v1.72.1
1.83.1
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
google.golang.org/grpc@v1.68.1
1.83.1
quay.io/metallb/speaker:v0.16.116561e96531e
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

2,129
cloudnative-pgcloudnative-pgVerified publisher0.29.01 of 1See more

cloudnative-pg cloudnative-pg 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.30.0a2701eb97cdd
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

118
rancherrancher-stable2.15.12 of 2See more

rancher rancher-stable 2.15.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
google.golang.org/grpc@v1.79.3
1.83.1
rancher/shell:v0.8.1f293af9c635f
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,456
oauth2-proxyoauth2-proxyOfficialVerified publisher10.7.01 of 1See more

oauth2-proxy oauth2-proxy 10.7.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.15.310a1165743a1
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

147
kedakedacore2.20.23 of 3See more

keda kedacore 2.20.2

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.20.2fe74c7b88495
google.golang.org/grpc@v1.81.1
1.83.1
ghcr.io/kedacore/keda-admission-webhooks:2.20.241f74102aba7
google.golang.org/grpc@v1.81.1
1.83.1
ghcr.io/kedacore/keda-metrics-apiserver:2.20.227286536a8a7
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

873
artifact-hubartifact-hubVerified publisher1.23.04 of 7See more

artifact-hub artifact-hub 1.23.0

4 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
aquasec/trivy:0.69.3bcc376de8d77
google.golang.org/grpc@v1.78.0
1.83.1
artifacthub/hub:v1.23.07d3a91c539dc
google.golang.org/grpc@v1.82.0
1.83.1
artifacthub/scanner:v1.23.02d8365601f0e
google.golang.org/grpc@v1.78.0
1.83.1
artifacthub/tracker:v1.23.05368d21a6e5c
google.golang.org/grpc@v1.75.1
1.83.1

Open the chart page →

10,782
kube-state-metricsprometheus-communityVerified publisher8.5.01 of 1See more

kube-state-metrics prometheus-community 8.5.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

82
alloygrafana1.12.11 of 2See more

alloy grafana 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/alloy:v1.19.2b8ec653c4423
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

1,139
prometheus-blackbox-exporterprometheus-communityOfficialVerified publisher11.18.01 of 1See more

prometheus-blackbox-exporter prometheus-community 11.18.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.28.0e753ff9f3fc4
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

594
deschedulerdescheduler0.36.01 of 1See more

descheduler descheduler 0.36.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/descheduler/descheduler:v0.36.07ca92c0a7b4f
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

569
argo-rolloutsargoOfficialVerified publisher2.43.11 of 1See more

argo-rollouts argo 2.43.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-rollouts:v1.10.0187630ba7228
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

115
argo-cdargo-cd-oci10.9.12 of 3See more

argo-cd argo-cd-oci 10.9.1

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.45.18499afd690c4
google.golang.org/grpc@v1.79.1
1.83.1
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

2,989
jaegerjaegertracingOfficialVerified publisher4.13.11 of 1See more

jaeger jaegertracing 4.13.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.20.046a886260e04
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

295
jupyterhubjupyterhubOfficialVerified publisher4.4.21 of 7See more

jupyterhub jupyterhub 4.4.2

1 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
google.golang.org/grpc@v1.58.3
1.83.1

Open the chart page →

7,909
mimir-distributedgrafana6.2.04 of 6See more

mimir-distributed grafana 6.2.0

4 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/mimir:3.2.0736f7459913d
google.golang.org/grpc@v1.82.1
1.83.1
grafana/rollout-operator:v0.38.132fe838b79dd
google.golang.org/grpc@v1.82.0
1.83.1
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
google.golang.org/grpc@v1.67.1
1.83.1
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

4,519
argocd-image-updaterargoOfficialVerified publisher1.3.11 of 1See more

argocd-image-updater argo 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

718
headlampheadlampOfficialVerified publisher0.45.01 of 1See more

headlamp headlamp 0.45.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.45.0db3f0e0fc58d
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

229
dexdexVerified publisher0.24.11 of 1See more

dex dex 0.24.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

1,765
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
google.golang.org/grpc@v1.79.2
1.83.1

Open the chart page →

30,167
falcofalcosecurity9.1.03 of 3See more

falco falcosecurity 9.1.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
falcosecurity/falco:0.44.1d0cfe422d6ac
google.golang.org/grpc@v1.79.3
1.83.1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
google.golang.org/grpc@v1.79.3
1.83.1
falcosecurity/falcoctl:0.13.00eeb79adc580
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

5,309
alertmanagerprometheus-communityOfficialVerified publisher1.43.11 of 1See more

alertmanager prometheus-community 1.43.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

63
kongkongOfficialVerified publisher3.4.11 of 2See more

kong kong 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:3.5979f12864a13
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

1,174
chartmuseumchartmuseumVerified publisher3.10.41 of 1See more

chartmuseum chartmuseum 3.10.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.3c81f105c3682
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

1,360
rook-cephrookOfficialVerified publisher1.20.71 of 2See more

rook-ceph rook 1.20.7

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/cephcsi/ceph-csi-operator:v1.0.4c62933fd4083
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,447
argo-eventsargoOfficialVerified publisher2.4.271 of 1See more

argo-events argo 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

969
victoria-metrics-k8s-stackvictoriametricsVerified publisher0.92.13 of 7See more

victoria-metrics-k8s-stack victoriametrics 0.92.1

3 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:13.1.17cb8c64c4d57
google.golang.org/grpc@v1.81.1
1.83.1
victoriametrics/operator:v0.74.17310c4a80b94
google.golang.org/grpc@v1.82.1
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,890
openebsopenebsOfficialVerified publisher4.6.115 of 35See more

openebs openebs 4.6.1

15 of the 35 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
google.golang.org/grpc@v1.71.0
1.83.1
grafana/loki:3.4.258a6c186ce78
google.golang.org/grpc@v1.70.0
1.83.1
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
google.golang.org/grpc@v1.71.1
1.83.1
openebs/lvm-driver:1.10.141f73aba7f31
google.golang.org/grpc@v1.79.3
1.83.1
openebs/provisioner-localpv:4.6.099f5116f5cb8
google.golang.org/grpc@v1.82.1
1.83.1
openebs/zfs-driver:2.11.116f1a74bb249
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
google.golang.org/grpc@v1.67.1
1.83.1
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
google.golang.org/grpc@v1.69.0
1.83.1
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
google.golang.org/grpc@v1.69.4
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
google.golang.org/grpc@v1.69.0
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
google.golang.org/grpc@v1.69.2
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
google.golang.org/grpc@v1.75.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
google.golang.org/grpc@v1.72.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
google.golang.org/grpc@v1.69.2
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
google.golang.org/grpc@v1.68.0
1.83.1

Open the chart page →

24,009
prometheus-adapterprometheus-communityOfficialVerified publisher5.3.01 of 1See more

prometheus-adapter prometheus-community 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
google.golang.org/grpc@v1.60.1
1.83.1

Open the chart page →

930
actions-runner-controlleractions-runner-controller0.23.71 of 2See more

actions-runner-controller actions-runner-controller 0.23.7

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
google.golang.org/grpc@v1.47.0
1.83.1

Open the chart page →

2,883
corednscorednsVerified publisher1.47.11 of 1See more

coredns coredns 1.47.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
coredns/coredns:1.14.6900f9c109f7a
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

330
apisixapisix2.17.01 of 3See more

apisix apisix 2.17.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
google.golang.org/grpc@v1.71.1
1.83.1

Open the chart page →

3,096
netdatanetdataVerified publisher3.7.1731 of 1See more

netdata netdata 3.7.173

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.0c45c71eb23ff
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

3,104
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

1,901
miniominio-official5.4.02 of 2See more

minio minio-official 5.4.0

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
google.golang.org/grpc@v1.67.1
1.83.1
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

2,483
opencostopencostOfficialVerified publisher2.5.311 of 2See more

opencost opencost 2.5.31

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost:1.121.2de2784434527
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

266
openfaasopenfaas15.0.132 of 6See more

openfaas openfaas 15.0.13

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v3.14.05ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

3,544
flux2fluxcd-community2.19.07 of 7See more

flux2 fluxcd-community 2.19.0

7 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
google.golang.org/grpc@v1.80.0
1.83.1
ghcr.io/fluxcd/helm-controller:v1.6.2e17ab0e5885d
google.golang.org/grpc@v1.80.0
1.83.1
ghcr.io/fluxcd/image-automation-controller:v1.2.26b0b16ab2115
google.golang.org/grpc@v1.80.0
1.83.1
ghcr.io/fluxcd/image-reflector-controller:v1.2.227e6bad1dac5
google.golang.org/grpc@v1.80.0
1.83.1
ghcr.io/fluxcd/kustomize-controller:v1.9.23aecec8bafdb
google.golang.org/grpc@v1.81.1
1.83.1
ghcr.io/fluxcd/notification-controller:v1.9.29ce503e7bcb8
google.golang.org/grpc@v1.81.1
1.83.1
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

2,957
vault-secrets-operatorhashicorpVerified publisher1.5.12 of 2See more

vault-secrets-operator hashicorp 1.5.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/vault-secrets-operator:1.5.1458c842add32
google.golang.org/grpc@v1.83.0
1.83.1
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

1,040
linkerd-vizlinkerd2Verified publisher30.12.111 of 5See more

linkerd-viz linkerd2 30.12.11

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.0b440bc0e8aa5
google.golang.org/grpc@v1.58.3
1.83.1

Open the chart page →

1,367
gatekeepergatekeeperVerified publisher3.23.11 of 3See more

gatekeeper gatekeeper 3.23.1

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.23.1dfc6fc78753f
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

496
snapshot-controllerpiraeus-chartsVerified publisher5.2.01 of 1See more

snapshot-controller piraeus-charts 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.6.081e79f205083
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

228

Container images carrying it

2,748 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
runatlantis/atlantis:v0.16.145fbaf7e207c
google.golang.org/grpc@v1.21.1
1.83.1
1
ruslanguns/metadata-injector-operator:v0.0.16c77e4675e07
google.golang.org/grpc@v1.65.0
1.83.1
1
ryuunosukeds3/orbital:latest0879f7261b10
google.golang.org/grpc@v1.70.0
1.83.1
1
sablierapp/sablier:1.16.1413704376656
google.golang.org/grpc@v1.82.1
1.83.1
1
sarwansharma/minio:v359d1da9385d1
google.golang.org/grpc@v1.46.0
1.83.1
1
scaleway/cert-manager-webhook-scaleway:v0.1.36d94c970e710
google.golang.org/grpc@v1.82.1
1.83.1
1
scaleway/scaleway-csi:v0.3.411135998e31c
google.golang.org/grpc@v1.73.0
1.83.1
1
scaleway/scaleway-secrets-store-csi:v0.1.19acc53a69962
google.golang.org/grpc@v1.83.0
1.83.1
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
google.golang.org/grpc@v1.53.0
1.83.1
1
seatsurfing/backend:1.119.39952e80048b0
google.golang.org/grpc@v1.82.1
1.83.1
1
securesystemsengineering/connaisseur:v3.12.038918befbdad
google.golang.org/grpc@v1.82.1
1.83.1
1
semaphoreui/semaphore:latest:v2.19.123996804607eb
google.golang.org/grpc@v1.76.0
1.83.1
1
semaphoreui/semaphore:v2.19.1498ad9bc7a2a0
google.golang.org/grpc@v1.76.0
1.83.1
1
semaphoreui/semaphore:v2.18.3e9260bfa8255
google.golang.org/grpc@v1.59.0
1.83.1
1
semitechnologies/weaviate:1.19.17a00d226f063
google.golang.org/grpc@v1.47.0
1.83.1
1
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
google.golang.org/grpc@v1.50.1
1.83.1
1
signoz/signoz:v0.141.1c10fa03e103c
google.golang.org/grpc@v1.82.1
1.83.1
1
signoz/signoz-otel-collector:v0.144.972aa1e4c1ec5
google.golang.org/grpc@v1.82.1
1.83.1
1
sikalabs/slu:v0.72.07bd267f30247
google.golang.org/grpc@v1.59.0
1.83.1
1
silkeh/alertmanager_matrix:0.6.1900010497f8c
google.golang.org/grpc@v1.78.0
1.83.1
1
simpleidserver/faasprometheus:0.0.425e378d57d78
google.golang.org/grpc@v1.40.0
1.83.1
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
google.golang.org/grpc@v1.58.3
1.83.1
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
google.golang.org/grpc@v1.62.1
1.83.1
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
google.golang.org/grpc@v1.39.0
1.83.1
1
snyk/kubernetes-monitor:2.23.26fb5ad76ce84e
google.golang.org/grpc@v1.80.0
1.83.1
1
softonic/homing-pigeon:0.9.6f26d467b7b82
google.golang.org/grpc@v1.73.0
1.83.1
1
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
google.golang.org/grpc@v1.81.1
1.83.1
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
google.golang.org/grpc@v1.43.0
1.83.1
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
google.golang.org/grpc@v1.23.1
1.83.1
1
sstarcher/helm-exporter:0.5.011769d01ba35
google.golang.org/grpc@v1.24.0
1.83.1
1
stakater/workshop-operator:v0.0.3897bf456cc97c
google.golang.org/grpc@v1.29.1
1.83.1
1
stakkato95/twitter-service-graphql:0.1.13cbe857234f2
google.golang.org/grpc@v1.46.2
1.83.1
1
stakkato95/twitter-service-users:0.1.1456049efee9a
google.golang.org/grpc@v1.46.2
1.83.1
1
stashapp/stash-box:latesta534c8afdf39
google.golang.org/grpc@v1.68.1
1.83.1
1
stevenweathers/thunderdome-planning-poker:latestc7eb7b10f186
google.golang.org/grpc@v1.79.3
1.83.1
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
google.golang.org/grpc@v1.35.0
1.83.1
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
google.golang.org/grpc@v1.23.1
1.83.1
1
streamnative/function-mesh:v0.28.077939c8aa269
google.golang.org/grpc@v1.79.3
1.83.1
1
streamnative/pulsar-resources-operator:v0.21.11886043c24d0
google.golang.org/grpc@v1.82.1
1.83.1
1
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
google.golang.org/grpc@v1.44.0
1.83.1
1
su541/cert-manager-desec-webhook:latest371ee33f83c1
google.golang.org/grpc@v1.51.0
1.83.1
1
supabase/gotrue:v2.189.0385184459f57
google.golang.org/grpc@v1.78.0
1.83.1
1
supabase/gotrue:v2.91.07174d551d720
google.golang.org/grpc@v1.53.0
1.83.1
1
supabase/gotrue:v2.163.0ba4ddc594b0b
google.golang.org/grpc@v1.63.2
1.83.1
1
superseriousbusiness/gotosocial:0.22.10078ca451dda
google.golang.org/grpc@v1.81.1
1.83.1
1
surajwarbhe/grafana:v185248611e9f1
google.golang.org/grpc@v1.27.1
1.83.1
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
google.golang.org/grpc@v1.45.0
1.83.1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
google.golang.org/grpc@v1.53.0
1.83.1
1
sysadminsmedia/homebox:0.26.056e880b62309
google.golang.org/grpc@v1.81.1
1.83.1
1
tailwarden/komiser:3.1.103f68c8ae7993
google.golang.org/grpc@v1.56.3
1.83.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.