StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,276
of 17,828 indexed, latest versions
Container images
2,733
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,276 of 17,828 indexed charts deploy, on 2,733 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,730
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed3
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,276 by stars
ChartLatestAffected imagesRadar Score
dnation-pingdnationcloud0.1.92 of 5See more

dnation-ping dnationcloud 0.1.9

2 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
google.golang.org/grpc@v1.33.1
1.83.1
prom/prometheus:v2.21.0d43417c260e5
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

10,475
docker-in-dockerdocker-in-docker0.0.31 of 2See more

docker-in-docker docker-in-docker 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/docker:24.0.2-dind1d148deae16a
google.golang.org/grpc@v1.56.0
1.83.1

Open the chart page →

2,595
docker-registrydocker-repository0.1.01 of 1See more

docker-registry docker-repository 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/registry:latestfd374bae807c
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

509
dockyarddockyardVerified publisher0.4.01 of 1See more

dockyard dockyard 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/kgma74/dockyard:0.4.0b40439329191
google.golang.org/grpc@v1.66.0
1.83.1

Open the chart page →

1,559
thermitedollarshaveclubOfficialVerified publisher0.1.171 of 1See more

thermite dollarshaveclub 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dollarshaveclub/thermite:0.0.31663cbf25fcfe
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

2,740
archerydoubanVerified publisher0.4.31 of 6See more

archery douban 0.4.3

1 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

5,864
dragonfly-stackdragonflyVerified publisher0.1.24 of 7See more

dragonfly-stack dragonfly 0.1.2

4 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
google.golang.org/grpc@v1.60.1
1.83.1
dragonflyoss/manager:v2.1.49c3ef7f10698d
google.golang.org/grpc@v1.64.0
1.83.1
dragonflyoss/scheduler:v2.1.49523785c77787
google.golang.org/grpc@v1.64.0
1.83.1
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

18,788
nydus-snapshotterdragonflyVerified publisher0.0.101 of 2See more

nydus-snapshotter dragonfly 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

3,669
egagenteginnovationsVerified publisher0.10.01 of 1See more

egagent eginnovations 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
eginnovations/agent:7.5.4e4dfe242fe9f
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

1,357
elaraelaraVerified publisher0.4.01 of 1See more

elara elara 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/sergeyslonimsky/elara:0.4.050fb24449dc3
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

83
elchi-stackelchi1.13.04 of 10See more

elchi-stack elchi 1.13.0

4 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:12.2.074144189b384
google.golang.org/grpc@v1.74.2
1.83.1
jhonbrownn/elchi-backend:v1.6.14-v0.14.0-envoy1.39.031aee9ba2c63
google.golang.org/grpc@v1.82.1
1.83.1
jhonbrownn/elchi-collector:v0.1.119fdd0724865e
google.golang.org/grpc@v1.80.0
1.83.1
otel/opentelemetry-collector-contrib:0.89.0995f17004231
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

15,785
enbuildenbuildVerified publisher0.0.502 of 6See more

enbuild enbuild 0.0.50

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
google.golang.org/grpc@v1.79.1
1.83.1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
google.golang.org/grpc@v1.79.1
1.83.1

Open the chart page →

31,614
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
google.golang.org/grpc@v1.69.4
1.83.1

Open the chart page →

3,121
ipfs-clusterethereum-helm-chartsVerified publisher0.1.141 of 3See more

ipfs-cluster ethereum-helm-charts 0.1.14

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:latesta83266c524f1
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

4,717
evccevccVerified publisher1.0.471 of 1See more

evcc evcc 1.0.47

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
evcc/evcc:0.300.8ddf2a25afce5
google.golang.org/grpc@v1.78.0
1.83.1

Open the chart page →

1,195
ext-postgres-operatorext-postgres-operatorVerified publisher3.0.01 of 1See more

ext-postgres-operator ext-postgres-operator 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/movetokube/postgres-operator:2.4.0def57d85a2da
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

401
falco-operatorfalcosecurity0.3.11 of 1See more

falco-operator falcosecurity 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
falcosecurity/falco-operator:0.4.18a99fcc57a57
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

386
ai-gatewayferro-labsOfficialVerified publisher1.2.01 of 1See more

ai-gateway ferro-labs 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/ferro-labs/ai-gateway:1.2.0baa285ec0fc9
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

123
file-manager-serverfile-manager-server1.11.01 of 1See more

file-manager-server file-manager-server 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
google.golang.org/grpc@v1.67.0
1.83.1

Open the chart page →

770
contentserverfoomoVerified publisher0.7.01 of 1See more

contentserver foomo 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
foomo/contentserver:1.21.0824f41463e9b
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

289
fqdn-controllerfqdn-controllerOfficialVerified publisher0.3.01 of 1See more

fqdn-controller fqdn-controller 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/konsole-is/fqdn-controller:0.3.08d5d41ab22aa
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

84
free5gcfree5gcVerified publisher0.1.32 of 12See more

free5gc free5gc 0.1.3

2 of the 12 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
free5gc/chf:v3.4.3e2a4dd98a4ed
google.golang.org/grpc@v1.56.3
1.83.1
free5gc/webui:v3.4.39adeb18492cb
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

10,717
fsmfsmOfficialVerified publisher0.2.111 of 5See more

fsm fsm 0.2.11

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flomesh/fsm-manager:0.2.1122f849c70b25
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

4,228
function-mesh-operatorfunction-mesh0.2.441 of 1See more

function-mesh-operator function-mesh 0.2.44

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
streamnative/function-mesh:v0.29.04176923db03c
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

200
memosgabe565Verified publisher0.17.01 of 1See more

memos gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/usememos/memos:0.24.04723d86e6797
google.golang.org/grpc@v1.69.2
1.83.1

Open the chart page →

1,477
dexgabibbo974.0.41 of 1See more

dex gabibbo97 4.0.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
google.golang.org/grpc@v1.34.0
1.83.1

Open the chart page →

3,399
garmgarmVerified publisher4.2.01 of 3See more

garm garm 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/igrikus/garm-operator:4.2.09e24d8a6a3b2
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

842
gateboardgateboard1.12.51 of 1See more

gateboard gateboard 1.12.5

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
udhos/gateboard:1.12.53acc0e7599bf
google.golang.org/grpc@v1.76.0
1.83.1

Open the chart page →

1,482
gateboard-discoverygateboard1.9.51 of 1See more

gateboard-discovery gateboard 1.9.5

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
udhos/gateboard-discovery:1.9.55567c9363c4c
google.golang.org/grpc@v1.76.0
1.83.1

Open the chart page →

1,209
gboxgboxVerified publisher1.0.51 of 2See more

gbox gbox 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gboxproxy/gbox:v1.0.63a9f4a711d5c
google.golang.org/grpc@v1.44.0
1.83.1

Open the chart page →

2,539
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
google.golang.org/grpc@v1.44.0
1.83.1

Open the chart page →

2,569
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
google.golang.org/grpc@v1.45.0
1.83.1

Open the chart page →

5,133
gigapipegigapipeVerified publisher0.3.01 of 1See more

gigapipe gigapipe 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/metrico/gigapipe:v4.1.6caeb2652ce5e
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

658
git-hubbygit-hubbyOfficialVerified publisher1.20.101 of 1See more

git-hubby git-hubby 1.20.10

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/interhyp/git-hubby:0.8.157361cd99d5ca
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

46
openbaogitlabVerified publisher0.18.11 of 1See more

openbao gitlab 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

1,827
temporalglasskubeVerified publisher0.45.2-gk.15 of 14See more

temporal glasskube 0.45.2-gk.1

5 of the 14 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
google.golang.org/grpc@v1.62.1
1.83.1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
google.golang.org/grpc@v1.65.0
1.83.1
temporalio/server:1.25.08a5798191dea
google.golang.org/grpc@v1.56.3
1.83.1
temporalio/ui:2.30.25c2a3645d09c
google.golang.org/grpc@v1.65.0
1.83.1
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

16,418
go-hello-world-chartgo-hello-worldVerified publisher1.8.31 of 1See more

go-hello-world-chart go-hello-world 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/wasilak/go-hello-world:1.8.366d353e7693f
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

767
gomenhashaigomenhashaiOfficialVerified publisher1.3.41 of 1See more

gomenhashai gomenhashai 1.3.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/gomenhashai/gomenhashai:v1.3.36f031172a5ec
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

642
gorse-enterprisegorse-io0.4.23 of 5See more

gorse-enterprise gorse-io 0.4.2

3 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
google.golang.org/grpc@v1.50.1
1.83.1
zhenghaoz/gorse-server:0.4.1239c565685b01
google.golang.org/grpc@v1.50.1
1.83.1
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
google.golang.org/grpc@v1.50.1
1.83.1

Open the chart page →

4,438
gotosocialgotosocialVerified publisher0.2.321 of 1See more

gotosocial gotosocial 0.2.32

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
superseriousbusiness/gotosocial:0.22.10078ca451dda
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

303
meta-monitoringgrafana1.3.01 of 2See more

meta-monitoring grafana 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/alloy:v1.4.306bdcbb51fc2
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

3,604
phlaregrafana0.5.41 of 1See more

phlare grafana 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/phlare:0.5.1330f990cdad9
google.golang.org/grpc@v1.44.0
1.83.1

Open the chart page →

2,091
gkograviteeioVerified publisher4.12.191 of 1See more

gko graviteeio 4.12.19

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
graviteeio/kubernetes-operator:4.12.1951dca8076ecc
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

146
armada-operatorgresearch0.7.01 of 2See more

armada-operator gresearch 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
google.golang.org/grpc@v1.58.3
1.83.1

Open the chart page →

1,583
carettagroundcover0.0.161 of 3See more

caretta groundcover 0.0.16

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/groundcover/grafana:9.3.18c65b333a3d3
google.golang.org/grpc@v1.45.0
1.83.1

Open the chart page →

6,821
oscargrycapOfficialVerified publisher4.1.31 of 2See more

oscar grycap 4.1.3

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/grycap/oscar:latest0c58ff972451
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

432
haproxy-unified-gatewayhaproxytechVerified publisher1.2.01 of 1See more

haproxy-unified-gateway haproxytech 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
haproxytech/haproxy-unified-gateway:1.0.7b9bffe2d0fd1
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

675
boundary-controllerhashicorpVerified publisher0.1.11 of 1See more

boundary-controller hashicorp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/boundary-enterprise:1.0.1-ent38d2f9bdee0d
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

304
boundary-workerhashicorpVerified publisher0.1.11 of 1See more

boundary-worker hashicorp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/boundary-enterprise:1.0.1-ent38d2f9bdee0d
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

304
terraform-cloud-operatorhashicorpVerified publisher2.5.01 of 2See more

terraform-cloud-operator hashicorp 2.5.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

1,478

Container images carrying it

2,733 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-84303.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.