StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,309
of 17,821 indexed, latest versions
Container images
2,767
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,309 of 17,821 indexed charts deploy, on 2,767 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,763
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,309 by stars
ChartLatestAffected imagesRadar Score
loki-stackcommon-chartsVerified publisher1.0.35 of 12See more

loki-stack common-charts 1.0.3

5 of the 12 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.0491b0578c049
google.golang.org/grpc@v1.81.1
1.83.1
grafana/grafana:13.1.17cb8c64c4d57
google.golang.org/grpc@v1.81.1
1.83.1
grafana/loki:3.6.1144148ad243c0
google.golang.org/grpc@v1.80.0
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.92.17d9247d23514
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

5,515
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

7,583
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

12,934
conjur-k8s-csi-providerconjure0.2.91 of 1See more

conjur-k8s-csi-provider conjure 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cyberark/conjur-k8s-csi-provider:latest737a967088d9
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

295
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

7,220
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

8,419
agent-forge-operatorcontainerooVerified publisher1.1.41 of 1See more

agent-forge-operator containeroo 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/containeroo/agent-forge-operator:v1.1.48f6d8acd134a
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

270
autovpacontainerooVerified publisher0.4.21 of 1See more

autovpa containeroo 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/containeroo/autovpa:v0.0.3425b801d8d1f7
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

312
cert-manager-webhook-bluecatcontainerooVerified publisher1.0.21 of 1See more

cert-manager-webhook-bluecat containeroo 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/containeroo/cert-manager-webhook-bluecat:latest96f82d5840d4
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

448
kube-ephemeral-container-exportercontainerooVerified publisher0.2.31 of 1See more

kube-ephemeral-container-exporter containeroo 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/containeroo/kube-ephemeral-container-exporter:v0.0.14b238f3c58d83
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

312
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.27.0828ee36cb13a
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

9,167
coordimap-agentcoordimap-agentVerified publisher0.4.31 of 1See more

coordimap-agent coordimap-agent 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
coordimap/coordimap-agent:latest7748fd0fae9f
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

771
cortezacorteza1.1.01 of 3See more

corteza corteza 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
google.golang.org/grpc@v1.61.1
1.83.1

Open the chart page →

8,514
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
google.golang.org/grpc@v1.61.1
1.83.1

Open the chart page →

4,711
cosanetcosanet1.0.01 of 1See more

cosanet cosanet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
google.golang.org/grpc@v1.75.0
1.83.1

Open the chart page →

2,255
ociscosmicrocks0.7.01 of 2See more

ocis cosmicrocks 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
owncloud/ocis:7.1.388e7c854517d
google.golang.org/grpc@v1.68.0
1.83.1

Open the chart page →

1,940
cosmo-traefikcosmoVerified publisher0.9.11 of 2See more

cosmo-traefik cosmo 0.9.1

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/traefik:v2.10.11489caffaedb
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

3,692
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/docker:dind3f3c01aaaebf
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

14,677
cospacecospace0.0.341 of 3See more

cospace cospace 0.0.34

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/twigex/cospace:lateste5ecfd607e42
google.golang.org/grpc@v1.62.0
1.83.1

Open the chart page →

2,317
couchbase-monitor-stackcouchbaseVerified publisher2.1.22 of 5See more

couchbase-monitor-stack couchbase 2.1.2

2 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:8.1.5b7dd9cd0e59d
google.golang.org/grpc@v1.39.0
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

6,978
grafana-mcpcowboysysopVerified publisher2.0.01 of 1See more

grafana-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
mcp/grafana:latest9362bcf6aa0e
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

1,177
katibcowboysysopVerified publisher2.4.23 of 4See more

katib cowboysysop 2.4.2

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
google.golang.org/grpc@v1.32.0
1.83.1
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
google.golang.org/grpc@v1.32.0
1.83.1
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
google.golang.org/grpc@v1.32.0
1.83.1

Open the chart page →

6,564
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
google.golang.org/grpc@v1.31.1
1.83.1

Open the chart page →

3,839
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

1,871
chalkularcrashoverride-helm-chartsVerified publisher0.0.81 of 1See more

chalkular crashoverride-helm-charts 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/chalkular-controller:v0.0.8d31986456626
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

54
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

4,633
electric-mailcryptexlabsVerified publisher0.0.11 of 5See more

electric-mail cryptexlabs 0.0.1

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

5,982
purple-piecryptexlabsVerified publisher0.0.11 of 4See more

purple-pie cryptexlabs 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

5,982
agent-sandboxcsghubVerified publisher0.5.61 of 1See more

agent-sandbox csghub 0.5.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.6dc23fb0d5624
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

37
csghubcsghubVerified publisher2.5.015 of 34See more

csghub csghub 2.5.0

15 of the 34 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
google.golang.org/grpc@v1.79.3
1.83.1
envoyproxy/gateway:v1.7.5156b7d32c73b
google.golang.org/grpc@v1.82.0
1.83.1
grafana/loki:3.4.258a6c186ce78
google.golang.org/grpc@v1.70.0
1.83.1
opencsghq/csghub-server:v2.5.0-ee587046575c2c
google.golang.org/grpc@v1.82.1
1.83.1
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
google.golang.org/grpc@v1.71.0
1.83.1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
google.golang.org/grpc@v1.67.1
1.83.1
opencsghq/gitlab-shell:v19.2.580a65ac370da
google.golang.org/grpc@v1.80.0
1.83.1
opencsghq/kube-state-metrics:v2.19.15ea147562ec8
google.golang.org/grpc@v1.79.3
1.83.1
opencsghq/lws:v0.6.1de15437db41b
google.golang.org/grpc@v1.65.0
1.83.1
opencsghq/prometheus:v3.13.00aac0d04749e
google.golang.org/grpc@v1.81.1
1.83.1
gcr.io/knative-releases/knative.dev/operator/cmd/operator:v1.22.3733f21dc06f9
google.golang.org/grpc@v1.80.0
1.83.1
gcr.io/knative-releases/knative.dev/operator/cmd/webhook:v1.22.366ae76179a80
google.golang.org/grpc@v1.80.0
1.83.1
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
google.golang.org/grpc@v1.72.2
1.83.1
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
google.golang.org/grpc@v1.72.2
1.83.1
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.4be477ba317d8
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

49,856
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
google.golang.org/grpc@v1.79.3
1.83.1
envoyproxy/gateway:v1.7.5156b7d32c73b
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

11,884
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.7.5156b7d32c73b
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

6,941
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

15,510
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

14,010
csi-driver-ipfscsi-driver-ipfs0.2.06 of 6See more

csi-driver-ipfs csi-driver-ipfs 0.2.0

6 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
google.golang.org/grpc@v1.75.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
google.golang.org/grpc@v1.78.0
1.83.1

Open the chart page →

3,700
ipfs-clustercsi-driver-ipfs0.2.02 of 2See more

ipfs-cluster csi-driver-ipfs 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:v1.1.6a83266c524f1
google.golang.org/grpc@v1.81.0
1.83.1
ipfs/kubo:v0.41.00661819c2e09
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,651
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

1,240
cw-container-insightcwci0.7.01 of 1See more

cw-container-insight cwci 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:latest-arm649dea6643715a
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

298
cloudflaredcyberjakeVerified publisher0.3.201 of 1See more

cloudflared cyberjake 0.3.20

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.6.16d91c121b803
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

556
irods-csi-drivercyverse0.12.04 of 4See more

irods-csi-driver cyverse 0.12.0

4 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cyverse/irods-csi-driver:v0.12.0aa69d105b292
google.golang.org/grpc@v1.81.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
google.golang.org/grpc@v1.59.0
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/grpc@v1.40.0
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
google.golang.org/grpc@v1.58.0
1.83.1

Open the chart page →

5,309
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
google.golang.org/grpc@v1.65.0
1.83.1
registry.k8s.io/kube-scheduler:v1.28.1146cf7475c8da
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

16,726
miniod4nVerified publisher5.2.12 of 2See more

minio d4n 5.2.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-04-29T09-56-05Zc574fac67f60
google.golang.org/grpc@v1.63.2
1.83.1
quay.io/minio/minio:RELEASE.2024-06-04T19-20-08Zc6b68f158628
google.golang.org/grpc@v1.63.2
1.83.1

Open the chart page →

2,801
cloudflareddamounVerified publisher3.3.01 of 1See more

cloudflared damoun 3.3.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.5.05d5f70a59d5e
google.golang.org/grpc@v1.63.0
1.83.1

Open the chart page →

1,345
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

3,248
dapr-agentsdapr-agents-devVerified publisher0.1.515 of 31See more

dapr-agents dapr-agents-dev 0.1.5

15 of the 31 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:12.3.39e1e77ade304
google.golang.org/grpc@v1.78.0
1.83.1
grafana/loki:3.6.5847c287ada0e
google.golang.org/grpc@v1.75.1
1.83.1
grafana/loki-canary:3.6.5fbb984bab741
google.golang.org/grpc@v1.75.1
1.83.1
grafana/tempo:2.9.065a578975943
google.golang.org/grpc@v1.75.0
1.83.1
mcp/grafana:latest9362bcf6aa0e
google.golang.org/grpc@v1.80.0
1.83.1
otel/opentelemetry-collector-contrib:0.145.0a7343f018690
google.golang.org/grpc@v1.78.0
1.83.1
ghcr.io/dapr/injector:1.17.0-rc.37a2fd888ed5f
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/dapr/operator:1.17.0-rc.3d5cc61cbe735
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/dapr/placement:1.17.0-rc.3a237b43cd5c6
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/dapr/scheduler:1.17.0-rc.36c62e01e736b
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/dapr/sentry:1.17.0-rc.3bf79b03591e0
google.golang.org/grpc@v1.73.0
1.83.1
ghcr.io/kagent-dev/kagent/tools:0.0.13c8882543f693
google.golang.org/grpc@v1.76.0
1.83.1
ghcr.io/kagent-dev/kmcp/controller:0.2.283276357d448
google.golang.org/grpc@v1.65.0
1.83.1
public.ecr.aws/diagrid-dev/diagrid-dashboard:latestf1348a65664a
google.golang.org/grpc@v1.80.0
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
google.golang.org/grpc@v1.75.1
1.83.1

Open the chart page →

22,571
dns-mesh-controllerdashdns2.0.81 of 2See more

dns-mesh-controller dashdns 2.0.8

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

1,111
dasherdasher0.1.11 of 1See more

dasher dasher 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/flohansen/dasher-server:latest7cde8c3fa2d1
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

1,097
dask-gatewaydask2026.3.01 of 2See more

dask-gateway dask 2026.3.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/traefik:3.3.5104204dadedf
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

2,165
cloudwatch-agent-prometheusdasmeta0.2.21 of 1See more

cloudwatch-agent-prometheus dasmeta 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
google.golang.org/grpc@v1.28.0
1.83.1

Open the chart page →

2,986
spqr-routerdasmeta0.1.11 of 1See more

spqr-router dasmeta 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
pgsharding/spqr-router:nightly-2.8.3-1839-f66048d84734940216d3
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

687

Container images carrying it

2,767 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
google.golang.org/grpc@v1.51.0
1.83.1
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
google.golang.org/grpc@v1.47.0
1.83.1
1
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
google.golang.org/grpc@v1.72.1
1.83.1
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
google.golang.org/grpc@v1.60.1
1.83.1
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
google.golang.org/grpc@v1.38.0
1.83.1
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
google.golang.org/grpc@v1.65.0
1.83.1
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
google.golang.org/grpc@v1.47.0
1.83.1
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
google.golang.org/grpc@v1.65.0
1.83.1
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
google.golang.org/grpc@v1.69.0
1.83.1
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
google.golang.org/grpc@v1.38.0
1.83.1
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
google.golang.org/grpc@v1.40.0
1.83.1
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
google.golang.org/grpc@v1.34.0
1.83.1
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
google.golang.org/grpc@v1.49.0
1.83.1
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
google.golang.org/grpc@v1.58.0
1.83.1
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
google.golang.org/grpc@v1.79.3
1.83.1
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
google.golang.org/grpc@v1.71.0
1.83.1
1
registry.k8s.io/sig-storage/objectstorage-sidecar:v0.2.2c7166a73a303
google.golang.org/grpc@v1.74.2
1.83.1
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.