StackRadar

CVE-2026-84303

Medium

Advisory

Published 1 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,276
of 17,828 indexed, latest versions
Container images
2,733
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,276 of 17,828 indexed charts deploy, on 2,733 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,730
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed3
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441

Charts affected

2,276 by stars
ChartLatestAffected imagesRadar Score
btrfs-nfs-csibtrfs-nfs-csi0.4.06 of 7See more

btrfs-nfs-csi btrfs-nfs-csi 0.4.0

6 of the 7 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
google.golang.org/grpc@v1.72.2
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
google.golang.org/grpc@v1.72.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
google.golang.org/grpc@v1.78.0
1.83.1

Open the chart page →

3,249
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

2,050
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
google.golang.org/grpc@v0.0.0-20170216003643-d0c32ee6a441
1.83.1

Open the chart page →

2,672
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
google.golang.org/grpc@v1.75.0
1.83.1

Open the chart page →

1,553
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

1,660
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

1,660
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
google.golang.org/grpc@v1.63.2
1.83.1

Open the chart page →

913
capsulecapsuleOfficialVerified publisher0.14.61 of 2See more

capsule capsule 0.14.6

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

1,239
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

1,818
cert-estuarycert-estuaryVerified publisher0.2.11 of 1See more

cert-estuary cert-estuary 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/hsn723/cert-estuary:0.2.00c4b6132b0ad
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

276
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
google.golang.org/grpc@v1.64.0
1.83.1
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
google.golang.org/grpc@v1.62.1
1.83.1
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
google.golang.org/grpc@v1.62.1
1.83.1
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
google.golang.org/grpc@v1.62.1
1.83.1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
google.golang.org/grpc@v1.62.1
1.83.1
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
google.golang.org/grpc@v1.62.1
1.83.1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
google.golang.org/grpc@v1.62.1
1.83.1

Open the chart page →

12,813
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
google.golang.org/grpc@v1.54.0
1.83.1

Open the chart page →

1,082
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
google.golang.org/grpc@v1.64.1
1.83.1

Open the chart page →

1,039
etcd-defragchristianhuthVerified publisher1.6.11 of 1See more

etcd-defrag christianhuth 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.7.13c66a5191d37
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

143
erpcchronicleVerified publisher0.7.01 of 1See more

erpc chronicle 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/erpc/erpc:0.1.18bfed3d49a08
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

391
clickhouse-operator-helmclickhouse-operator0.0.71 of 1See more

clickhouse-operator-helm clickhouse-operator 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/clickhouse/clickhouse-operator:v0.0.7d51ca53f0967
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

118
cloudflare-tunnelcloudflare-tunnelVerified publisher0.16.61 of 1See more

cloudflare-tunnel cloudflare-tunnel 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.9.0ff69a2225ad7
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

356
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220201 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

1 of the 9 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
prom/prometheus:v2.21.0d43417c260e5
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

4,267
cnpg-sandboxcloudnative-pgVerified publisher0.6.12 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
google.golang.org/grpc@v1.41.0
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

7,601
grafanacloudposse0.2.61 of 1See more

grafana cloudposse 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:latestac461fb352ab
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

599
openstack-manila-csicloud-provider-openstack2.36.35 of 5See more

openstack-manila-csi cloud-provider-openstack 2.36.3

5 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
google.golang.org/grpc@v1.80.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
google.golang.org/grpc@v1.72.1
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
google.golang.org/grpc@v1.72.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
google.golang.org/grpc@v1.69.2
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v8.4.0c7e0a3718832
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

3,786
cloudttycloudtty0.8.102 of 2See more

cloudtty cloudtty 0.8.10

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell:v0.8.1023e8d178e02c
google.golang.org/grpc@v1.72.1
1.83.1
ghcr.io/cloudtty/cloudshell-operator:v0.8.1014f036e33ef1
google.golang.org/grpc@v1.54.1
1.83.1

Open the chart page →

3,029
cluster-api-provider-oxidecluster-api-provider-oxide0.2.31 of 1See more

cluster-api-provider-oxide cluster-api-provider-oxide 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/oxidecomputer/cluster-api-provider-oxide:0.2.37b05d3bbfbfa
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

129
clustereye-stackclustereyeVerified publisher0.1.11 of 5See more

clustereye-stack clustereye 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
johnblack77/clustereye-api:latest16c25fd2128c
google.golang.org/grpc@v1.71.0
1.83.1

Open the chart page →

4,636
clusternet-hubclusternet1.0.01 of 1See more

clusternet-hub clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-hub:v1.0.059f75504c5d4
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

1,556
clusternet-schedulerclusternet1.0.01 of 1See more

clusternet-scheduler clusternet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/clusternet/clusternet-scheduler:v1.0.0a6ae5aff81ce
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

1,556
cluster-setupcluster-setup1.5.04 of 8See more

cluster-setup cluster-setup 1.5.0

4 of the 8 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
google.golang.org/grpc@v1.71.0
1.83.1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
google.golang.org/grpc@v1.71.0
1.83.1
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
google.golang.org/grpc@v1.69.2
1.83.1
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
google.golang.org/grpc@v1.69.2
1.83.1

Open the chart page →

10,479
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
google.golang.org/grpc@v1.67.1
1.83.1
istio/pilot:1.24.2-distroless137e44e3d1d2
google.golang.org/grpc@v1.67.1
1.83.1
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
google.golang.org/grpc@v1.63.2
1.83.1
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

4,839
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
google.golang.org/grpc@v1.67.1
1.83.1
istio/pilot:1.24.2-distroless137e44e3d1d2
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

2,380
maintenancecodewithemadVerified publisher0.1.61 of 1See more

maintenance codewithemad 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/caddy:2.9-alpineb4e3952384eb
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

1,495
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

7,315
cortex-tenantcortex-tenantVerified publisher0.8.11 of 1See more

cortex-tenant cortex-tenant 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/blind-oracle/cortex-tenant:v2.0.09f8896ffc15b
google.golang.org/grpc@v1.71.0
1.83.1

Open the chart page →

786
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

6,484
chalk-operatorcrashoverride-helm-chartsVerified publisher0.1.11 of 1See more

chalk-operator crashoverride-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/chalk-operator:v0.1.128eee62e9bfa
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

382
cronjob-scale-down-operatorcronschedules0.4.41 of 1See more

cronjob-scale-down-operator cronschedules 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/cronschedules/cronjob-scale-down-operator:0.4.41c4e803d7169
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

451
revadcs3orgOfficialVerified publisher1.6.11 of 1See more

revad cs3org 1.6.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
google.golang.org/grpc@v1.52.0
1.83.1

Open the chart page →

1,714
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
google.golang.org/grpc@v1.22.1
1.83.1
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
google.golang.org/grpc@v1.29.1
1.83.1
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
google.golang.org/grpc@v1.40.0
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
google.golang.org/grpc@v1.40.0
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/grpc@v1.36.0
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

15,938
cview-issuercview-issuerVerified publisher0.0.421 of 1See more

cview-issuer cview-issuer 0.0.42

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
devsecurely/cview-issuer:0.0.42eecd4314e933
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

426
cyphernetes-operatorcyphernetes-operatorVerified publisher0.1.01 of 1See more

cyphernetes-operator cyphernetes-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
google.golang.org/grpc@v1.67.3
1.83.1

Open the chart page →

512
aibrixdanchevVerified publisher0.7.02 of 5See more

aibrix danchev 0.7.0

2 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
aibrix/controller-manager:v0.7.076aabbbfda79
google.golang.org/grpc@v1.65.0
1.83.1
aibrix/gateway-plugins:v0.7.05b93ea4c753a
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

5,263
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

38,823
dbrepodbrepo1.13.33 of 25See more

dbrepo dbrepo 1.13.3

3 of the 25 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
google.golang.org/grpc@v1.66.0
1.83.1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
google.golang.org/grpc@v1.65.0
1.83.1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
google.golang.org/grpc@v1.72.0
1.83.1

Open the chart page →

53,784
deckarddeckardOfficial0.1.81 of 3See more

deckard deckard 0.1.8

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
blipai/deckard:0.1.8db8cd873d0eb
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

385
dregsydeliveryheroVerified publisher0.1.51 of 1See more

dregsy deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
google.golang.org/grpc@v1.44.0
1.83.1

Open the chart page →

2,979
developer-operatordeveloper-operatorVerified publisher2.1.21 of 1See more

developer-operator developer-operator 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

1,909
trivy-operatordevopstalesVerified publisher2.5.01 of 1See more

trivy-operator devopstales 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
devopstales/trivy-operator:2.575136aa7a26e
google.golang.org/grpc@v1.50.1
1.83.1

Open the chart page →

5,609
calicodevtron0.1.13 of 4See more

calico devtron 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

10,099
dex-serverdex-server1.19.11 of 3See more

dex-server dex-server 1.19.1

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
dexidp/dex:v2.39.1-distroless43655afd1a8f
google.golang.org/grpc@v1.62.1
1.83.1

Open the chart page →

2,246
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

7,790
myappdl-grafana-webappVerified publisher0.1.01 of 2See more

myapp dl-grafana-webapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
onkar17/grafana:latestaef3ebd6e24e
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

2,527

Container images carrying it

2,733 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

No deployed image carries CVE-2026-84303.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.