StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,275
of 17,813 indexed, latest versions
Container images
2,703
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,275 of 17,813 indexed charts deploy, on 2,703 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,700
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed3
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,275 by stars
ChartLatestAffected imagesRadar Score
pet-battle-nsffpetbattle0.0.22 of 4See more

pet-battle-nsff petbattle 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
minio/mc:latesta7fe349ef4bd
google.golang.org/grpc@v1.71.0
1.83.1
minio/minio:latest14cea493d9a3
google.golang.org/grpc@v1.71.0
1.83.1

Open the chart page →

3,887
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
google.golang.org/grpc@v1.35.0
1.83.1

Open the chart page →

15,479
pgcopydb-operatorpgcopydb-operatorVerified publisher0.13.31 of 1See more

pgcopydb-operator pgcopydb-operator 0.13.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/ydixken/pgcopydb-operator:v0.13.306096c6ec357
google.golang.org/grpc@v1.82.2
1.83.1

Open the chart page →

41
loki-stackphntom2.10.22 of 2See more

loki-stack phntom 2.10.2

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/loki:2.4.2b3af8ead67d7
google.golang.org/grpc@v1.40.0
1.83.1
grafana/promtail:2.4.2626900031c4e
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

5,726
npre-essentialsphntom0.1.606 of 22See more

npre-essentials phntom 0.1.60

6 of the 22 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
google.golang.org/grpc@v1.44.0
1.83.1
grafana/promtail:2.7.0c16c710f7333
google.golang.org/grpc@v1.45.0
1.83.1
phntom/chartmuseum:v0.15.29242b4df9e65
google.golang.org/grpc@v1.47.0
1.83.1
phntom/oauth2-proxy:v7.3.48ea656a2a895
google.golang.org/grpc@v1.27.0
1.83.1
quay.io/groundcover/grafana:9.3.18c65b333a3d3
google.golang.org/grpc@v1.45.0
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.61.1cd7d1a82ef00
google.golang.org/grpc@v1.50.1
1.83.1

Open the chart page →

26,903
pii-shield-operatorpii-shieldVerified publisher2.2.41 of 1See more

pii-shield-operator pii-shield 2.2.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/pii-shield/pii-shield-operator:2.2.4a634aa90da30
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

49
blockmeta-servicepinaxVerified publisher0.0.31 of 1See more

blockmeta-service pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
google.golang.org/grpc@v1.61.0
1.83.1

Open the chart page →

1,698
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
google.golang.org/grpc@v1.48.0
1.83.1

Open the chart page →

3,562
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
google.golang.org/grpc@v1.72.0
1.83.1

Open the chart page →

7,236
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

58,368
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

58,309
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
google.golang.org/grpc@v1.48.0
1.83.1

Open the chart page →

5,000
pipekit-agentpipekit-helmOfficialVerified publisher8.0.11 of 1See more

pipekit-agent pipekit-helm 8.0.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
pipekit13/agent:v8.0.1b969a930b439
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

131
pixie-operator-chartpixie0.1.71 of 3See more

pixie-operator-chart pixie 0.1.7

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned1b6002156f56
google.golang.org/grpc@v1.60.1
1.83.1

Open the chart page →

1,915
pixie-operator-helm2-chartpixie0.1.21 of 2See more

pixie-operator-helm2-chart pixie 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinnedf9ea8cef95ac
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,769
planectlplanectlVerified publisher0.7.03 of 10See more

planectl planectl 0.7.0

3 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
google.golang.org/grpc@v1.49.0
1.83.1
pulumi/pulumi-kubernetes-operator:v2.5.17dace4491358
google.golang.org/grpc@v1.72.1
1.83.1
quay.io/argoproj/argocd:v2.14.115fc69e31c755
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

26,457
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
google.golang.org/grpc@v1.24.0
1.83.1

Open the chart page →

11,164
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

13,114
agentpolyaxon2.17.01 of 4See more

agent polyaxon 2.17.0

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
polyaxon/polyaxon-operator:2.17.07664c1cebb9d
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

8,967
polyaxonpolyaxon2.17.01 of 5See more

polyaxon polyaxon 2.17.0

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
polyaxon/polyaxon-operator:2.17.07664c1cebb9d
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

12,749
portagerportager0.5.01 of 1See more

portager portager 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/jarodr47/portager:0.5.06a7a61b37568
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

151
beylaportefaix-hub0.1.01 of 1See more

beyla portefaix-hub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/beyla:1.3.336d07f8d276e
google.golang.org/grpc@v1.61.0
1.83.1

Open the chart page →

2,732
cloudflare-tunnelportefaix-hub0.4.01 of 1See more

cloudflare-tunnel portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.8.314d9c6b01b29
google.golang.org/grpc@v1.63.0
1.83.1

Open the chart page →

1,344
liftbridgepozetron0.1.11 of 1See more

liftbridge pozetron 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
google.golang.org/grpc@v1.24.0
1.83.1

Open the chart page →

3,175
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
google.golang.org/grpc@v1.22.0
1.83.1

Open the chart page →

9,616
oauth2-proxypresto-loadbalancer4.3.181 of 2See more

oauth2-proxy presto-loadbalancer 4.3.18

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

3,965
prismeai-appsprismeai0.7.11 of 4See more

prismeai-apps prismeai 0.7.1

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

2,782
prismeai-coreprismeai1.12.11 of 7See more

prismeai-core prismeai 1.12.1

1 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

3,591
procestypecatalogusprocestypecatalogus1.1.01 of 4See more

procestypecatalogus procestypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

7,441
productenendienstencatalogusproductenendienstencatalogus1.0.01 of 3See more

productenendienstencatalogus productenendienstencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

7,521
prometheus-optimizerprometheus-optimizer0.2.221 of 1See more

prometheus-optimizer prometheus-optimizer 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

4,472
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

8,735
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

7,521
kspanpuckpuck0.2.41 of 1See more

kspan puckpuck 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

1,688
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
google.golang.org/grpc@v1.48.0
1.83.1

Open the chart page →

4,221
pulumi-esc-csi-providerpulumi-esc-csi-provider0.1.61 of 1See more

pulumi-esc-csi-provider pulumi-esc-csi-provider 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/pulumi/pulumi-esc-csi-provider:0.1.13fb058e93502
google.golang.org/grpc@v1.69.2
1.83.1

Open the chart page →

823
pulumi-exporterpulumi-exporter0.1.61 of 1See more

pulumi-exporter pulumi-exporter 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/pulumi-labs/pulumi-exporter:0.1.45415d5a46e7d
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

134
game-serverpvillaverdeVerified publisher1.0.61 of 1See more

game-server pvillaverde 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/itzg/minecraft-server:latest46919d151d39
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

4,216
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
sarwansharma/minio:v359d1da9385d1
google.golang.org/grpc@v1.46.0
1.83.1

Open the chart page →

6,703
loki-stackpyalive-cdmswebappVerified publisher2.6.54 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
grafana/loki:2.5.0f9ef133793af
google.golang.org/grpc@v1.44.0
1.83.1
grafana/promtail:2.4.2626900031c4e
google.golang.org/grpc@v1.40.0
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

6,585
qualys-scannerqualys-helm-chartVerified publisher2.1.01 of 1See more

qualys-scanner qualys-helm-chart 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
qualys/qscanner:5.1.0-59ff255352422
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

259
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/loki:3.3.28af2de1abbdd
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

4,534
apisixquench-apisixVerified publisher0.0.31 of 2See more

apisix quench-apisix 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/etcddigest-pinned05765ee83074
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

118
chartmuseumquench-chartmuseumVerified publisher0.0.11 of 1See more

chartmuseum quench-chartmuseum 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/chartmuseumdigest-pinned3af8698e0524
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

102
coolifyquench-coolifyVerified publisher0.0.181 of 4See more

coolify quench-coolify 0.0.18

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/coolify-realtimedigest-pinnedf128e512c9c0
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

546
coolify-realtimequench-coolify-realtimeVerified publisher0.0.71 of 1See more

coolify-realtime quench-coolify-realtime 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/coolify-realtimedigest-pinnedf128e512c9c0
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

344
dexquench-dexVerified publisher0.0.111 of 1See more

dex quench-dex 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/dexdigest-pinned8b41a7c5f1bf
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

102
grafanaquench-grafanaVerified publisher0.0.121 of 1See more

grafana quench-grafana 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/grafanadigest-pinned3ccc56791c8a
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

177
harbor-observabilityquench-harbor-observabilityVerified publisher0.0.102 of 2See more

harbor-observability quench-harbor-observability 0.0.10

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/grafanadigest-pinned3ccc56791c8a
google.golang.org/grpc@v1.82.1
1.83.1
ghcr.io/quenchworks/images/prometheusdigest-pinnede9037c190bc1
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

281
identity-stackquench-identity-stackVerified publisher0.0.131 of 3See more

identity-stack quench-identity-stack 0.0.13

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/oauth2-proxydigest-pinned6c479b032dcd
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

292

Container images carrying it

2,703 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
google.golang.org/grpc@v1.79.3
1.83.1
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
google.golang.org/grpc@v1.71.0
1.83.1
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
google.golang.org/grpc@v1.74.2
1.83.1
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.