StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,278
of 17,828 indexed, latest versions
Container images
2,737
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,278 of 17,828 indexed charts deploy, on 2,737 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,734
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed3
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,278 by stars
ChartLatestAffected imagesRadar Score
hawkhawk1.1.51 of 4See more

hawk hawk 1.1.5

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
google.golang.org/grpc@v1.42.0
1.83.1

Open the chart page →

13,679
cert-manager-webhook-hetznerhcloud0.9.01 of 1See more

cert-manager-webhook-hetzner hcloud 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hetzner/cert-manager-webhook-hetzner:v0.9.0b64db89ba4c1
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

220
headscale-uiheadscale-uiVerified publisher0.2.91 of 1See more

headscale-ui headscale-ui 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/gurucomputing/headscale-ui:2026.03.17015f5ba04bcb
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,502
uptime-kumahelmforgeVerified publisher1.5.131 of 1See more

uptime-kuma helmforge 1.5.13

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
google.golang.org/grpc@v1.79.2
1.83.1

Open the chart page →

30,728
velerohelmforgeVerified publisher1.4.102 of 2See more

velero helmforge 1.4.10

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
velero/velero:v1.18.237396519f399
google.golang.org/grpc@v1.81.1
1.83.1
velero/velero-plugin-for-aws:v1.14.07e82f717f44e
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

1,462
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
google.golang.org/grpc@v1.60.0
1.83.1

Open the chart page →

4,251
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
google.golang.org/grpc@v1.30.0
1.83.1

Open the chart page →

6,990
spirehelm-spireVerified publisher0.30.27 of 10See more

spire helm-spire 0.30.2

7 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
google.golang.org/grpc@v1.83.0
1.83.1
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
google.golang.org/grpc@v1.71.0
1.83.1
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
google.golang.org/grpc@v1.76.0
1.83.1
ghcr.io/spiffe/spire-agent:1.15.341b0dcd8b258
google.golang.org/grpc@v1.83.0
1.83.1
ghcr.io/spiffe/spire-controller-manager:0.7.0d7b9e710f542
google.golang.org/grpc@v1.82.1
1.83.1
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
google.golang.org/grpc@v1.83.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

1,688
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
google.golang.org/grpc@v1.58.3
1.83.1

Open the chart page →

16,517
buildbarnhermetiq-buildbarnVerified publisher0.9.22 of 4See more

buildbarn hermetiq-buildbarn 0.9.2

2 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/buildbarn/bb-scheduler:20260908T142432Z-77f7642f627ab242890
google.golang.org/grpc@v1.81.1
1.83.1
ghcr.io/buildbarn/bb-storage:20260908T142448Z-db6204132ebc54b769b
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

202
hiverhiverVerified publisher0.1.459 of 10See more

hiver hiver 0.1.45

9 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hiversh/antigravity:0.1.45-microvm0e36d98402bc
google.golang.org/grpc@v1.80.0
1.83.1
hiversh/browser:0.1.45-microvmb5048c6342ce
google.golang.org/grpc@v1.80.0
1.83.1
hiversh/claude:0.1.45-microvm2fbf9f264498
google.golang.org/grpc@v1.80.0
1.83.1
hiversh/codex:0.1.45-microvm4f43130f51e5
google.golang.org/grpc@v1.80.0
1.83.1
hiversh/controller:0.1.45b0b85f8942c7
google.golang.org/grpc@v1.80.0
1.83.1
hiversh/copilot:0.1.45-microvm50c07b84f298
google.golang.org/grpc@v1.80.0
1.83.1
hiversh/node:0.1.45-alpine-microvm836a37641941
google.golang.org/grpc@v1.80.0
1.83.1
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
google.golang.org/grpc@v1.80.0
1.83.1
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

21,549
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
google.golang.org/grpc@v1.37.0
1.83.1

Open the chart page →

2,921
holoinsightholoinsight0.2.52 of 6See more

holoinsight holoinsight 0.2.5

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
holoinsight/otelcontribcol:latest42ba8dc3113c
google.golang.org/grpc@v1.54.0
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

27,901
holoinsight-agentholoinsight0.2.51 of 2See more

holoinsight-agent holoinsight 0.2.5

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
holoinsight/agent:latest5c3994e742f8
google.golang.org/grpc@v1.46.2
1.83.1

Open the chart page →

1,804
hpe-greenlake-file-csi-driverhpe-storageVerified publisher2.6.45 of 7See more

hpe-greenlake-file-csi-driver hpe-storage 2.6.4

5 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
google.golang.org/grpc@v1.69.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
google.golang.org/grpc@v1.72.1
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.1.0e5900dc98b0d
google.golang.org/grpc@v1.75.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
google.golang.org/grpc@v1.65.0
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

6,314
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
google.golang.org/grpc@v1.63.2
1.83.1

Open the chart page →

4,373
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

1,580
hybrid-csi-pluginhybrid-csi-plugin0.1.111 of 1See more

hybrid-csi-plugin hybrid-csi-plugin 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/hybrid-csi-provisioner:v0.3.1221e07794a8a
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

380
idle-reaperidle-reaperVerified publisher0.1.41 of 1See more

idle-reaper idle-reaper 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/b100to/idle-reaper:0.1.447b4a0e091f0
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

148
webhook-broker-chartimytech0.2.41 of 1See more

webhook-broker-chart imytech 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

1,254
inference-manager-serverinference-manager-server1.46.01 of 1See more

inference-manager-server inference-manager-server 1.46.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/inference-manager-server:1.46.00bbb5f5ddf71
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

257
interlinkinterlink0.6.11 of 2See more

interlink interlink 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/interlink-hq/interlink/virtual-kubelet-inttw:latest0e05a7b49c33
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

2,494
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

74,823
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

74,898
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

74,843
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

74,843
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

75,124
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

1,820
kubernetes-event-exporteritakurahVerified publisher0.2.31 of 1See more

kubernetes-event-exporter itakurah 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/itakurah/kubernetes-event-exporter:v1.78abb52b66557
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

1,142
statpingitscontainedVerified publisher0.1.91 of 1See more

statping itscontained 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
statping/statping:v0.90.6532f26fffca46
google.golang.org/grpc@v1.28.1
1.83.1

Open the chart page →

3,538
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
google.golang.org/grpc@v1.46.2
1.83.1

Open the chart page →

9,413
rclonejmmaloney42.3.211 of 1See more

rclone jmmaloney4 2.3.21

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
rclone/rclone:1.66.0a693c46a6b8b
google.golang.org/grpc@v1.60.1
1.83.1

Open the chart page →

1,762
job-manager-dispatcherjob-manager-dispatcher1.27.01 of 1See more

job-manager-dispatcher job-manager-dispatcher 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-dispatcher:1.27.0582508903cb0
google.golang.org/grpc@v1.67.0
1.83.1

Open the chart page →

479
job-manager-serverjob-manager-server1.27.01 of 1See more

job-manager-server job-manager-server 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
google.golang.org/grpc@v1.67.0
1.83.1

Open the chart page →

757
hncjouveVerified publisher0.8.31 of 1See more

hnc jouve 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

1,078
joylive-injectorjoyliveOfficialVerified publisher1.3.51 of 2See more

joylive-injector joylive 1.3.5

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
otel/opentelemetry-collector:0.100.09e36620d6c2c
google.golang.org/grpc@v1.63.2
1.83.1

Open the chart page →

1,290
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
google.golang.org/grpc@v1.54.0
1.83.1

Open the chart page →

3,383
junos-exporterjunos-exporter0.16.21 of 1See more

junos-exporter junos-exporter 0.16.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
czerwonk/junos_exporter:v0.16.2cb2279ae53d7
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

203
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.3210 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

10 of the 17 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/alloy:v1.14.0f50931848bd8
google.golang.org/grpc@v1.78.0
1.83.1
grafana/grafana:12.3.12175aaa91c96
google.golang.org/grpc@v1.76.0
1.83.1
grafana/loki:3.6.73c8fd3570dd9
google.golang.org/grpc@v1.75.1
1.83.1
grafana/loki-canary:3.6.70dac7d5cb383
google.golang.org/grpc@v1.75.1
1.83.1
grafana/tempo:2.9.065a578975943
google.golang.org/grpc@v1.75.0
1.83.1
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
google.golang.org/grpc@v1.67.1
1.83.1
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
google.golang.org/grpc@v1.69.0
1.83.1
quay.io/prometheus/alertmanager:v0.31.188b605de9aba
google.golang.org/grpc@v1.78.0
1.83.1
quay.io/prometheus/prometheus:v3.10.07571a304e67f
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
google.golang.org/grpc@v1.75.1
1.83.1

Open the chart page →

15,797
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

8,134
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

5,782
mongodb-operatorkeiailabVerified publisher1.16.91 of 1See more

mongodb-operator keiailab 1.16.9

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/keiailab/mongodb-operator:v1.16.9cf6d86e057bb
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

127
valkey-operatorkeiailabVerified publisher1.5.21 of 1See more

valkey-operator keiailab 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/keiailab/valkey-operator:1.5.249b5aef82877
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

127
keycloak-client-operatorkeycloak-client-operator0.9.11 of 1See more

keycloak-client-operator keycloak-client-operator 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.gitlab.com/lenitech/k8s-operator/keycloak-client:v0.6.19065cdd80035
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

522
netbirdkitstream-netbird0.7.11 of 3See more

netbird kitstream-netbird 0.7.1

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
netbirdio/netbird-server:0.78.2ac6317722f6f
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

833
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
google.golang.org/grpc@v1.69.2
1.83.1

Open the chart page →

11,405
kube-arguskube-argusOfficialVerified publisher0.0.1-s2z1 of 1See more

kube-argus kube-argus 0.0.1-s2z

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/manishchaudhary101/kube-argus:latest8e3869d31c70
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

383
cert-managerkubeblocksVerified publisher1.17.22 of 4See more

cert-manager kubeblocks 1.17.2

2 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
google.golang.org/grpc@v1.69.2
1.83.1

Open the chart page →

2,930
ks-corekubeblocksVerified publisher1.1.32 of 5See more

ks-core kubeblocks 1.1.3

2 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kubesphere/ks-extensions-museum:latest29681958f220
google.golang.org/grpc@v1.58.3
1.83.1
kubesphere/kubectl:v1.27.1649b445b1b732
google.golang.org/grpc@v1.58.3
1.83.1

Open the chart page →

4,741
kubebrowsekubebrowse1.7.01 of 5See more

kubebrowse kubebrowse 1.7.0

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

2,933

Container images carrying it

2,737 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-84303.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.