StackRadar

CVE-2026-84303

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,288
of 17,790 indexed, latest versions
Container images
2,765
deployed by those charts
Fix available
1 of 2
affected packages

gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

Carried by container images the latest versions of 2,288 of 17,790 indexed charts deploy, on 2,765 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,761
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
OSV records
GHSA-qc2q-p7wx-3px3UBUNTU-CVE-2026-84303
Also known as
GO-2026-6441
Trending
Rank 47 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,288 by stars
ChartLatestAffected imagesRadar Score
mission-control-tenantflanksourceVerified publisher1.0.923 of 3See more

mission-control-tenant flanksource 1.0.92

3 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
google.golang.org/grpc@v1.40.0
1.83.1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
google.golang.org/grpc@v1.57.0
1.83.1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
google.golang.org/grpc@v1.55.0
1.83.1

Open the chart page →

5,709
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

3,481
fluxcd-helm-upgraderfluxcd-helm-upgraderVerified publisher0.7.71 of 1See more

fluxcd-helm-upgrader fluxcd-helm-upgrader 0.7.7

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
kenchrcum/fluxcd-helm-upgrader:0.7.7c326e28a8f5f
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

2,429
flyte-devboxflyte0.1.07 of 13See more

flyte-devbox flyte 0.1.0

7 of the 13 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinned0d5f740b4224
google.golang.org/grpc@v1.71.1
1.83.1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned697668be7893
google.golang.org/grpc@v1.71.1
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned031408ec516f
google.golang.org/grpc@v1.71.1
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned3502bb5aa60f
google.golang.org/grpc@v1.71.1
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpadigest-pinned7405faeb7636
google.golang.org/grpc@v1.71.1
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
google.golang.org/grpc@v1.71.1
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned50831d9aaa69
google.golang.org/grpc@v1.71.1
1.83.1

Open the chart page →

4,678
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
google.golang.org/grpc@v1.51.0
1.83.1

Open the chart page →

4,650
free5gc-chffree5gc-chfVerified publisher0.1.31 of 1See more

free5gc-chf free5gc-chf 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
free5gc/chf:v3.4.3e2a4dd98a4ed
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

1,003
free5gc-webuifree5gc-webuiVerified publisher0.1.31 of 1See more

free5gc-webui free5gc-webui 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
free5gc/webui:v3.4.39adeb18492cb
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

1,256
castsponsorskipgabe565Verified publisher0.8.11 of 1See more

castsponsorskip gabe565 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/gabe565/castsponsorskip:0.8.15f7b4c6dd299
google.golang.org/grpc@v1.68.0
1.83.1

Open the chart page →

1,237
generic-device-plugingabe565Verified publisher0.1.31 of 1See more

generic-device-plugin gabe565 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:latestdc192e164c69
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

260
smarter-device-managergabe565Verified publisher0.5.21 of 1See more

smarter-device-manager gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

1,226
transsmutegabe565Verified publisher1.1.01 of 1See more

transsmute gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/gabe565/transsmute:latestc8ac95a30c31
google.golang.org/grpc@v1.71.0
1.83.1

Open the chart page →

801
galoygaloymoney0.34.73 of 24See more

galoy galoymoney 0.34.7

3 of the 24 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
google.golang.org/grpc@v1.59.0
1.83.1
oryd/kratos:v1.0.0d06fc5845f63
google.golang.org/grpc@v1.54.0
1.83.1
oryd/oathkeeper:v0.40.6e8cb9b79a89c
google.golang.org/grpc@v1.56.1
1.83.1

Open the chart page →

8,700
galoy-depsgaloymoney0.10.203 of 9See more

galoy-deps galoymoney 0.10.20

3 of the 9 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
google.golang.org/grpc@v1.67.1
1.83.1
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
google.golang.org/grpc@v1.60.1
1.83.1
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
google.golang.org/grpc@v1.60.1
1.83.1

Open the chart page →

11,982
lndgaloymoney0.10.61 of 3See more

lnd galoymoney 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

2,161
monitoringgaloymoney0.12.212 of 6See more

monitoring galoymoney 0.12.21

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
google.golang.org/grpc@v1.66.0
1.83.1
quay.io/prometheus/prometheus:v2.55.0378f4e037035
google.golang.org/grpc@v1.66.0
1.83.1

Open the chart page →

5,310
galoygaloymoney20.34.73 of 24See more

galoy galoymoney2 0.34.7

3 of the 24 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
google.golang.org/grpc@v1.59.0
1.83.1
oryd/kratos:v1.0.0d06fc5845f63
google.golang.org/grpc@v1.54.0
1.83.1
oryd/oathkeeper:v0.40.6e8cb9b79a89c
google.golang.org/grpc@v1.56.1
1.83.1

Open the chart page →

8,700
galoy-depsgaloymoney20.10.203 of 9See more

galoy-deps galoymoney2 0.10.20

3 of the 9 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
google.golang.org/grpc@v1.67.1
1.83.1
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
google.golang.org/grpc@v1.60.1
1.83.1
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
google.golang.org/grpc@v1.60.1
1.83.1

Open the chart page →

11,982
lndgaloymoney20.10.61 of 3See more

lnd galoymoney2 0.10.6

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

2,161
monitoringgaloymoney20.12.212 of 6See more

monitoring galoymoney2 0.12.21

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
google.golang.org/grpc@v1.66.0
1.83.1
quay.io/prometheus/prometheus:v2.55.0378f4e037035
google.golang.org/grpc@v1.66.0
1.83.1

Open the chart page →

5,310
gameserver-operatorgameserver-operator0.3.01 of 1See more

gameserver-operator gameserver-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/idebeijer/gameserver-operator:latest1b099cfe9e5e
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

376
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

3,243
searxgeek-cookbookVerified publisher5.6.21 of 4See more

searx geek-cookbook 5.6.2

1 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/caddy:2.2.0-alpine7367adca165f
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

7,476
webhook-receivergeek-cookbookVerified publisher0.0.11 of 1See more

webhook-receiver geek-cookbook 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

1,368
clickhouse-movoorgeneral-helm-chartsVerified publisher0.0.11 of 1See more

clickhouse-movoor general-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ethpandaops/clickhouse-movoor:latestc0e6cc6542c1
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

136
cloudflare-tunnelgeneral-helm-chartsVerified publisher0.2.01 of 1See more

cloudflare-tunnel general-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:latest51c9cefcb456
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

553
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
google.golang.org/grpc@v1.44.0
1.83.1

Open the chart page →

4,558
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
google.golang.org/grpc@v1.39.0
1.83.1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
google.golang.org/grpc@v1.39.0
1.83.1

Open the chart page →

16,854
ghostghostVerified publisher0.1.02 of 4See more

ghost ghost 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
cloudflare/cloudflared:latest51c9cefcb456
google.golang.org/grpc@v1.83.0
1.83.1
litestream/litestream:0.3c5a1e1b01916
google.golang.org/grpc@v1.57.0
1.83.1

Open the chart page →

9,071
gitlab-goproxygitlab-goproxy0.2.21 of 1See more

gitlab-goproxy gitlab-goproxy 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
google.golang.org/grpc@v1.46.0
1.83.1

Open the chart page →

1,332
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
google.golang.org/grpc@v1.54.0
1.83.1

Open the chart page →

2,616
glassflow-etlglassflowVerified publisher0.5.214 of 16See more

glassflow-etl glassflow 0.5.21

4 of the 16 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.108.0923eb1cfae32
google.golang.org/grpc@v1.65.0
1.83.1
ghcr.io/glassflow/glassflow-etl-be:v3.2.020f066d0f631
google.golang.org/grpc@v1.80.0
1.83.1
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
google.golang.org/grpc@v1.75.0
1.83.1
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
google.golang.org/grpc@v1.74.2
1.83.1

Open the chart page →

12,115
glassflow-operatorglassflow-operatorVerified publisher0.8.51 of 3See more

glassflow-operator glassflow-operator 0.8.5

1 of the 3 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
google.golang.org/grpc@v1.75.0
1.83.1

Open the chart page →

770
glauthglauthVerified publisher0.3.171 of 2See more

glauth glauth 0.3.17

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

2,634
gnp-stackgnp-stack0.0.53 of 14See more

gnp-stack gnp-stack 0.0.5

3 of the 14 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:12.2.135c41e0fd029
google.golang.org/grpc@v1.74.2
1.83.1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.17.02bbc91556733
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

7,683
go-file-servergo-file-server1.0.01 of 2See more

go-file-server go-file-server 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
goccx/go-file-server:latestf4b3ebea0303
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

2,222
gorsegorse-io0.4.23 of 4See more

gorse gorse-io 0.4.2

3 of the 4 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
google.golang.org/grpc@v1.50.1
1.83.1
zhenghaoz/gorse-server:0.4.1239c565685b01
google.golang.org/grpc@v1.50.1
1.83.1
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
google.golang.org/grpc@v1.50.1
1.83.1

Open the chart page →

4,401
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
google.golang.org/grpc@v1.40.0
1.83.1

Open the chart page →

22,587
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
google.golang.org/grpc@v1.40.0
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

24,379
harborgpg-dev1.18.34 of 8See more

harbor gpg-dev 1.18.3

4 of the 8 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.14.3a30e5a8be3d9
google.golang.org/grpc@v1.69.4
1.83.1
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
google.golang.org/grpc@v1.69.4
1.83.1
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
google.golang.org/grpc@v1.69.4
1.83.1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
google.golang.org/grpc@v1.78.0
1.83.1

Open the chart page →

3,406
jaegergpg-dev3.3.33 of 5See more

jaeger gpg-dev 3.3.3

3 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
google.golang.org/grpc@v1.60.0
1.83.1
jaegertracing/jaeger-collector:1.53.07f1269222903
google.golang.org/grpc@v1.60.0
1.83.1
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
google.golang.org/grpc@v1.60.0
1.83.1

Open the chart page →

19,311
kube-prometheus-stackgpg-dev84.0.02 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

2 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:13.0.10f86bada30d6
google.golang.org/grpc@v1.79.3
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
google.golang.org/grpc@v1.75.1
1.83.1

Open the chart page →

4,303
metrics-servergpg-dev3.12.11 of 1See more

metrics-server gpg-dev 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

1,078
opentelemetry-demogpg-dev0.33.88 of 27See more

opentelemetry-demo gpg-dev 0.33.8

8 of the 27 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
google.golang.org/grpc@v1.66.0
1.83.1
jaegertracing/all-in-one:1.53.060e65bfffe1f
google.golang.org/grpc@v1.60.0
1.83.1
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
google.golang.org/grpc@v1.67.1
1.83.1
ghcr.io/open-feature/flagd:v0.11.1a7ea52f87446
google.golang.org/grpc@v1.65.0
1.83.1
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
google.golang.org/grpc@v1.64.0
1.83.1
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
google.golang.org/grpc@v1.64.0
1.83.1
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
google.golang.org/grpc@v1.60.1
1.83.1
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

49,362
prometheusgpg-dev29.2.13 of 6See more

prometheus gpg-dev 29.2.1

3 of the 6 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.32.058e117eabcce
google.golang.org/grpc@v1.80.0
1.83.1
quay.io/prometheus/prometheus:v3.11.2cd37346c9745
google.golang.org/grpc@v1.79.3
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
google.golang.org/grpc@v1.75.1
1.83.1

Open the chart page →

3,281
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,280
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
google.golang.org/grpc@v1.77.0
1.83.1

Open the chart page →

1,562
cloudcost-exportergrafana1.1.131 of 1See more

cloudcost-exporter grafana 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/cloudcost-exporter:v1.12.0eeb2cfecb23e
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

160
grafana-cloud-onboardinggrafana0.4.73 of 5See more

grafana-cloud-onboarding grafana 0.4.7

3 of the 5 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/beyla-k8s-cache:253b2f561cb1b
google.golang.org/grpc@v1.77.0
1.83.1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
google.golang.org/grpc@v1.79.3
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
google.golang.org/grpc@v1.75.1
1.83.1

Open the chart page →

4,681
grafana-samplinggrafana1.1.71 of 2See more

grafana-sampling grafana 1.1.7

1 of the 2 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
google.golang.org/grpc@v1.75.0
1.83.1

Open the chart page →

3,370
k8s-injection-controllergrafana0.2.11 of 1See more

k8s-injection-controller grafana 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-84303.

Container imageDigestPackageFixed in
ghcr.io/grafana/k8s-injection-controller:0.2.0c5bad40655a3
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

130

Container images carrying it

2,765 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
google.golang.org/grpc@v1.51.0
1.83.1
2
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
google.golang.org/grpc@v1.51.0
1.83.1
2
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
google.golang.org/grpc@v1.49.0
1.83.1
2
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
google.golang.org/grpc@v1.51.0
1.83.1
2
public.ecr.aws/gravitational/tbot-distroless:18.11.04ba5ace31fea
google.golang.org/grpc@v1.82.1
1.83.1
2
public.ecr.aws/p3k6k6h3/mdai-event-hub:0.1.1118cae836e9c7
google.golang.org/grpc@v1.80.0
1.83.1
2
public.ecr.aws/p3k6k6h3/mdai-gateway:0.1.100dfb323978f6
google.golang.org/grpc@v1.80.0
1.83.1
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
google.golang.org/grpc@v1.65.0
1.83.1
2
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
google.golang.org/grpc@v1.72.2
1.83.1
2
quay.io/argoproj/argo-rollouts:v1.10.0187630ba7228
google.golang.org/grpc@v1.80.0
1.83.1
2
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
google.golang.org/grpc@v1.82.1
1.83.1
2
quay.io/brancz/kube-rbac-proxy:v0.20.0147cb28fea35
google.golang.org/grpc@v1.72.1
1.83.1
2
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
google.golang.org/grpc@v1.47.0
1.83.1
2
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
google.golang.org/grpc@v1.47.0
1.83.1
2
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
google.golang.org/grpc@v1.65.0
1.83.1
2
quay.io/brancz/kube-rbac-proxy:v0.22.1e8cad21b2f9a
google.golang.org/grpc@v1.80.0
1.83.1
2
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
google.golang.org/grpc@v1.81.0
1.83.1
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
google.golang.org/grpc@v1.48.0
1.83.1
2
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
google.golang.org/grpc@v1.82.1
1.83.1
2
quay.io/cilium/tetragon-operator:v1.7.1cd8b71f6860e
google.golang.org/grpc@v1.82.1
1.83.1
2
quay.io/coreos/etcd:v3.5.628cb0630cb85
google.golang.org/grpc@v1.41.0
1.83.1
2
quay.io/coreos/etcd:v3.7.13c66a5191d37
google.golang.org/grpc@v1.82.1
1.83.1
2
quay.io/coreos/etcd:v3.6.12702d7b4881c6
google.golang.org/grpc@v1.79.3
1.83.1
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
google.golang.org/grpc@v1.26.0
1.83.1
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
google.golang.org/grpc@v1.45.0
1.83.1
2
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
google.golang.org/grpc@v1.44.0
1.83.1
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
google.golang.org/grpc@v1.45.0
1.83.1
2
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
google.golang.org/grpc@v1.44.0
1.83.1
2
quay.io/jetstack/cert-manager-controller:v1.17.22c314feeb5e8
google.golang.org/grpc@v1.69.2
1.83.1
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
google.golang.org/grpc@v1.60.1
1.83.1
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
google.golang.org/grpc@v1.58.3
1.83.1
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
google.golang.org/grpc@v1.49.0
1.83.1
2
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
google.golang.org/grpc@v1.64.1
1.83.1
2
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
google.golang.org/grpc@v1.49.0
1.83.1
2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
google.golang.org/grpc@v1.58.3
1.83.1
2
quay.io/jetstack/cert-manager-webhook:v1.17.237b16a9dff00
google.golang.org/grpc@v1.69.2
1.83.1
2
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
google.golang.org/grpc@v1.49.0
1.83.1
2
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
google.golang.org/grpc@v1.60.1
1.83.1
2
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
google.golang.org/grpc@v1.64.1
1.83.1
2
quay.io/kuadrant/dns-operator:v0.17.2da9ff8211856
google.golang.org/grpc@v1.82.1
1.83.1
2
quay.io/kubevirt/kubevirt-cloud-controller-manager:v0.6.037ad4c475941
google.golang.org/grpc@v1.78.0
1.83.1
2
quay.io/kubevirt/kubevirt-csi-driver:latest7b31b21b3f1e
google.golang.org/grpc@v1.80.0
1.83.1
2
quay.io/metallb/controller:v0.16.1f51ab515de9c
google.golang.org/grpc@v1.72.1
1.83.1
2
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
google.golang.org/grpc@v1.68.1
1.83.1
2
quay.io/metallb/speaker:v0.16.116561e96531e
google.golang.org/grpc@v1.72.1
1.83.1
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
google.golang.org/grpc@v1.58.0
1.83.1
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
google.golang.org/grpc@v1.50.1
1.83.1
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
google.golang.org/grpc@v1.58.0
1.83.1
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
google.golang.org/grpc@v1.54.0
1.83.1
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
google.golang.org/grpc@v1.52.3
1.83.1
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.