StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,309
of 17,821 indexed, latest versions
Container images
2,767
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,309 of 17,821 indexed charts deploy, on 2,767 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,763
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,309 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

9,743
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,528
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,077

Container images carrying it

2,767 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
google.golang.org/grpc@v1.48.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler105bdd14ecaa
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler2ef460356b17
google.golang.org/grpc@v1.28.1
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.13.134796e9f760b
google.golang.org/grpc@v1.60.1
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
google.golang.org/grpc@v1.48.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdb6ceff2aab4
google.golang.org/grpc@v1.33.1
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
google.golang.org/grpc@v1.48.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller30ce73388ae5
google.golang.org/grpc@v1.28.1
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.13.153d9aa4d2c7a
google.golang.org/grpc@v1.60.1
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
google.golang.org/grpc@v1.48.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerb2cd45b8a8a4
google.golang.org/grpc@v1.33.1
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerbac158dfb0c7
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mappinge384a295069b
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.10.2f66c41ad7a73
google.golang.org/grpc@v1.48.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook15f1ce7f35b4
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.10.27368aaddf2be
google.golang.org/grpc@v1.48.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook1282a399cbb9
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.10.24305209ce498
google.golang.org/grpc@v1.48.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.13.1700c69915dc7
google.golang.org/grpc@v1.60.1
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookd27b4495ccc3
google.golang.org/grpc@v1.33.1
1.83.1
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookf16c0e022203
google.golang.org/grpc@v1.28.1
1.83.1
1
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
google.golang.org/grpc@v1.67.1
1.83.1
1
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
google.golang.org/grpc@v1.27.1
1.83.1
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
google.golang.org/grpc@v1.59.0
1.83.1
1
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
google.golang.org/grpc@v1.27.1
1.83.1
1
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
google.golang.org/grpc@v1.69.4
1.83.1
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
google.golang.org/grpc@v1.19.1
1.83.1
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
google.golang.org/grpc@v1.19.1
1.83.1
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
google.golang.org/grpc@v1.60.1
1.83.1
1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
google.golang.org/grpc@v1.60.1
1.83.1
1
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
google.golang.org/grpc@v1.60.1
1.83.1
1
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
google.golang.org/grpc@v1.60.1
1.83.1
1
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
google.golang.org/grpc@v1.44.0
1.83.1
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
google.golang.org/grpc@v1.55.0
1.83.1
1
gcr.io/projectsigstore/cosigned784518ff3ee7
google.golang.org/grpc@v1.46.0
1.83.1
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
google.golang.org/grpc@v1.46.0
1.83.1
1
ghcr.io/absmach/magistrala/ui-backend:latestb3986672fa02
google.golang.org/grpc@v1.83.0
1.83.1
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
google.golang.org/grpc@v1.59.0
1.83.1
1
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
google.golang.org/grpc@v1.70.0
1.83.1
1
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
google.golang.org/grpc@v1.68.0
1.83.1
1
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
google.golang.org/grpc@v1.68.0
1.83.1
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.