StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,312
of 17,828 indexed, latest versions
Container images
2,773
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,312 of 17,828 indexed charts deploy, on 2,773 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,769
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,312 by stars
ChartLatestAffected imagesRadar Score
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

1,061
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

13,934
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

402
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

9,769
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

9,530
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.83.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.83.1
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.83.1
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

8,003
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.83.1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

5,077

Container images carrying it

2,773 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
google.golang.org/grpc@v1.23.0
1.83.1
2
amazon/aws-fsx-csi-driver:latestc9b14856fd22
google.golang.org/grpc@v1.23.1
1.83.1
2
aquasec/trivy:0.74.062b1e65e8869
google.golang.org/grpc@v1.82.1
1.83.1
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
google.golang.org/grpc@v1.47.0
1.83.1
2
casbin/casdoor:3.62.17729da148c61
google.golang.org/grpc@v1.79.3
1.83.1
2
cesanta/docker_auth:1.6.04d16885f3d4c
google.golang.org/grpc@v1.21.1
1.83.1
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
google.golang.org/grpc@v1.23.1
1.83.1
2
cloudflare/cloudflared:2026.6.16d91c121b803
google.golang.org/grpc@v1.81.1
1.83.1
2
coredns/coredns:1.13.19b9128672209
google.golang.org/grpc@v1.75.1
1.83.1
2
crate/crate_adapter:latestb8d89fa5d19b
google.golang.org/grpc@v1.37.0
1.83.1
2
cs3org/revad:v1.19.03b57a34a7dfd
google.golang.org/grpc@v1.47.0
1.83.1
2
cs3org/revad:v1.24.0e80a4d67b352
google.golang.org/grpc@v1.52.0
1.83.1
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
google.golang.org/grpc@v1.26.0
1.83.1
2
datawire/emissary:3.12.21f67a1292d2a
google.golang.org/grpc@v1.67.0
1.83.1
2
devopsfaith/krakend:latestf8bdaa8a1a43
google.golang.org/grpc@v1.66.0
1.83.1
2
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
google.golang.org/grpc@v1.36.0
1.83.1
2
dunglas/mercure:v0:v0.24.2916834e49961
google.golang.org/grpc@v1.81.1
1.83.1
2
epamedp/cd-pipeline-operator:2.32.0fc858071b7a1
google.golang.org/grpc@v1.82.1
1.83.1
2
epamedp/codebase-operator:2.35.0295a008abcef
google.golang.org/grpc@v1.82.1
1.83.1
2
epamedp/edp-tekton:0.27.088189f16f94b
google.golang.org/grpc@v1.82.1
1.83.1
2
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.83.1
2
fluxcd/flux-cli:v2.9.5704d55295355
google.golang.org/grpc@v1.80.0
1.83.1
2
free5gc/chf:v3.4.3e2a4dd98a4ed
google.golang.org/grpc@v1.56.3
1.83.1
2
free5gc/webui:v3.4.39adeb18492cb
google.golang.org/grpc@v1.56.3
1.83.1
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
google.golang.org/grpc@v1.45.0
1.83.1
2
gomods/athens:v0.11.0efb811df7844
google.golang.org/grpc@v1.26.0
1.83.1
2
gotenberg/gotenberg:8.36.087c16b9f3642
google.golang.org/grpc@v1.83.0
1.83.1
2
governify/dashboard:lateste83a17ba5038
google.golang.org/grpc@v1.40.0
1.83.1
2
grafana/agent-operator:v0.25.1a136c6208aa3
google.golang.org/grpc@v1.44.0
1.83.1
2
grafana/alloy:v1.8.17790f6f7fbd8
google.golang.org/grpc@v1.71.0
1.83.1
2
grafana/alloy:v1.12.2f94b1c82957a
google.golang.org/grpc@v1.76.0
1.83.1
2
grafana/grafana:9.2.4057896e23443
google.golang.org/grpc@v1.45.0
1.83.1
2
grafana/grafana:11.1.0079600c9517b
google.golang.org/grpc@v1.64.0
1.83.1
2
grafana/grafana:13.0.10f86bada30d6
google.golang.org/grpc@v1.79.3
1.83.1
2
grafana/grafana:12.3.12175aaa91c96
google.golang.org/grpc@v1.76.0
1.83.1
2
grafana/grafana:8.5.042d3e6bc1865
google.golang.org/grpc@v1.42.0
1.83.1
2
grafana/grafana:7.3.5511bc20bfcd1
google.golang.org/grpc@v1.33.1
1.83.1
2
grafana/grafana:11.1.4886b56d5534e
google.golang.org/grpc@v1.64.0
1.83.1
2
grafana/grafana:12.3.39e1e77ade304
google.golang.org/grpc@v1.78.0
1.83.1
2
grafana/grafana:11.4.0d8ea37798ccc
google.golang.org/grpc@v1.66.0
1.83.1
2
grafana/grafana:12.4.1e932bd6ed0e0
google.golang.org/grpc@v1.78.0
1.83.1
2
grafana/loki:3.6.5847c287ada0e
google.golang.org/grpc@v1.75.1
1.83.1
2
grafana/loki:1.5.0922b3f412fdd
google.golang.org/grpc@v1.26.0
1.83.1
2
grafana/loki:3.7.7:latestd70e4659623f
google.golang.org/grpc@v1.82.1
1.83.1
2
grafana/loki:3.1.0d947e68a84d9
google.golang.org/grpc@v1.62.1
1.83.1
2
grafana/loki:2.5.0f9ef133793af
google.golang.org/grpc@v1.44.0
1.83.1
2
grafana/mimir:3.2.0736f7459913d
google.golang.org/grpc@v1.82.1
1.83.1
2
grafana/promtail:1.5.046e88d390cd6
google.golang.org/grpc@v1.26.0
1.83.1
2
grafana/promtail:3.0.0d3de3da9431c
google.golang.org/grpc@v1.62.1
1.83.1
2
grafana/tempo:2.5.0f0200a9bff6d
google.golang.org/grpc@v1.63.2
1.83.1
2

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.