StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,309
of 17,821 indexed, latest versions
Container images
2,767
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,309 of 17,821 indexed charts deploy, on 2,767 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,763
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,309 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

9,743
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,528
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,077

Container images carrying it

2,767 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
treeverse/lakefs:1.86.0fb7a0d90f77e
google.golang.org/grpc@v1.81.1
1.83.1
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
google.golang.org/grpc@v1.39.0
1.83.1
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
google.golang.org/grpc@v1.36.0
1.83.1
1
tusproject/tusd:v1.10.01e457b59fd5b
google.golang.org/grpc@v1.50.0
1.83.1
1
tusproject/tusd:v1.13.0f8088058b80f
google.golang.org/grpc@v1.57.0
1.83.1
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
google.golang.org/grpc@v1.31.0
1.83.1
1
twinproduction/gatus:v5.34.03fff895e77d3
google.golang.org/grpc@v1.77.0
1.83.1
1
tykio/portal:v1.18.092509e00e618
google.golang.org/grpc@v1.80.0
1.83.1
1
tykio/tyk-operator:v1.4.2e13d37f298b7
google.golang.org/grpc@v1.79.3
1.83.1
1
udhos/apiping:1.5.041ab9bae6f3b
google.golang.org/grpc@v1.77.0
1.83.1
1
udhos/gateboard:1.12.53acc0e7599bf
google.golang.org/grpc@v1.76.0
1.83.1
1
udhos/gateboard-discovery:1.9.55567c9363c4c
google.golang.org/grpc@v1.76.0
1.83.1
1
udhos/kubecache:0.14.1f44ef986df49
google.golang.org/grpc@v1.82.1
1.83.1
1
udhos/lambdaping:1.0.46bd2cf2ac732
google.golang.org/grpc@v1.69.2
1.83.1
1
udhos/secrets:1.0.6daa2b4eaac09
google.golang.org/grpc@v1.71.1
1.83.1
1
udhos/snsping:1.2.96ae70677b6a3
google.golang.org/grpc@v1.69.2
1.83.1
1
uptrace/uptrace:2.0.234a02c3b2d12
google.golang.org/grpc@v1.73.0
1.83.1
1
v2fly/v2fly-core:latestd06727b221fe
google.golang.org/grpc@v1.76.0
1.83.1
1
vdaas/vald-agent-ngt:v1.8.032e3695fe585
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-benchmark-operator:v1.8.006b4a9b4ab06
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-discoverer-k8s:v1.8.0f6495f38ae92
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-lb-gateway:v1.8.061009e319a9a
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-manager-index:v1.8.0ab881d2262d8
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-operator:latest0c3dcd4974f6
google.golang.org/grpc@v1.83.0
1.83.1
1
vearch/vearch:3.3.40768af33f9d9
google.golang.org/grpc@v1.26.0
1.83.1
1
veecode/devportala72cf5cb47b8
google.golang.org/grpc@v1.79.3
1.83.1
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
google.golang.org/grpc@v1.58.3
1.83.1
1
velero/velero:v1.9.0277fbfaf8dcf
google.golang.org/grpc@v1.38.0
1.83.1
1
velero/velero:v1.8.18d784580931c
google.golang.org/grpc@v1.40.0
1.83.1
1
velero/velero:v1.18.0e4d1e79be2ee
google.golang.org/grpc@v1.77.0
1.83.1
1
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
google.golang.org/grpc@v1.40.0
1.83.1
1
velero/velero-plugin-for-aws:v1.14.07e82f717f44e
google.golang.org/grpc@v1.77.0
1.83.1
1
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
google.golang.org/grpc@v1.27.0
1.83.1
1
volcanosh/vc-scheduler:v1.15.2afab36286a17
google.golang.org/grpc@v1.79.3
1.83.1
1
volcanosh/vc-scheduler:v1.12.1b24ea8af2d16
google.golang.org/grpc@v1.57.0
1.83.1
1
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
google.golang.org/grpc@v1.57.0
1.83.1
1
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
google.golang.org/grpc@v1.27.0
1.83.1
1
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
google.golang.org/grpc@v1.27.1
1.83.1
1
vultr/vultr-csi:v0.3.041d26735d437
google.golang.org/grpc@v1.40.0
1.83.1
1
wait4x/wait4x:3.3.14dcd86307de1
google.golang.org/grpc@v1.71.0
1.83.1
1
wallarm/aih-scanner:2.7.11f1cb26db1f5b
google.golang.org/grpc@v1.75.0
1.83.1
1
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
google.golang.org/grpc@v1.62.1
1.83.1
1
wallarm/node-native-processing:0.25.860828c36ee6d
google.golang.org/grpc@v1.83.0
1.83.1
1
wallarm/node-native-processing:0.23.07db2da8fce0b
google.golang.org/grpc@v1.79.1
1.83.1
1
wavefronthq/prometheus-storage-adapter:latestded77b38c7c6
google.golang.org/grpc@v1.56.3
1.83.1
1
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
google.golang.org/grpc@v1.38.0
1.83.1
1
wazuh/wazuh-manager:4.11.11da5c38c6a78
google.golang.org/grpc@v1.29.1
1.83.1
1
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/grpc@v1.29.1
1.83.1
1
wazuh/wazuh-manager:4.14.45a065930682d
google.golang.org/grpc@v1.29.1
1.83.1
1
wazuh/wazuh-manager:4.14.3f09282d281f6
google.golang.org/grpc@v1.29.1
1.83.1
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.