StackRadar

CVE-2026-84304

High

Advisory

Published 1 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,288
of 17,790 indexed, latest versions
Container images
2,766
deployed by those charts
Fix available
2 of 3
affected packages

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

Carried by container images the latest versions of 2,288 of 17,790 indexed charts deploy, on 2,766 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,761
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
kubernetes-1.34apk1.34.11-r21.34.11-r61
OSV records
CGA-2w5g-qvhw-4526GHSA-vp52-pcj8-j9qcUBUNTU-CVE-2026-84304
Also known as
CGA-2w99-fmrr-7c59, CGA-37h3-vm4r-h6gp, CGA-4rmw-5272-crfm, CGA-8mvv-qrfc-pwm2, CGA-94hq-vh86-c5h5, CGA-9c5q-7vcp-52g3, CGA-j2mp-r3h6-gw3j, CGA-j357-xxg6-gx2j, CGA-w54h-8g59-4jxp, CGA-wj6g-63h9-g67r, CGA-xmw7-6f5r-33jj, GO-2026-6348
Trending
Rank 35 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

2,288 by stars
ChartLatestAffected imagesRadar Score
missing-container-metricsmissing-container-metrics0.1.11 of 1See more

missing-container-metrics missing-container-metrics 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
google.golang.org/grpc@v1.36.0
1.83.1

Open the chart page →

2,418
olmolmVerified publisher0.45.01 of 1See more

olm olm 0.45.0

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/operator-framework/olm:v0.45.0f228c7a6b8c5
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

441
opencostopencost-ociOfficialVerified publisher2.5.311 of 2See more

opencost opencost-oci 2.5.31

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost:1.121.2de2784434527
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

273
ketoory0.64.01 of 1See more

keto ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
oryd/keto:v26.2.0bfdb8b9e283a
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

824
oathkeeperory0.64.01 of 1See more

oathkeeper ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
oryd/oathkeeper:v26.2.0467329abde34
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

776
pmmpercona1.9.11 of 1See more

pmm percona 1.9.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
percona/pmm-server:3.9.1003f9c25f842
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

797
redis-enterprise-operatorredis-enterprise-operator-officialOfficialVerified publisher8.0.18-111 of 1See more

redis-enterprise-operator redis-enterprise-operator-official 8.0.18-11

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
redislabs/operator:8.0.18-119078e713bb6a
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

921
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

1,364
rekorsigstoreVerified publisher1.8.64 of 9See more

rekor sigstore 1.8.6

4 of the 9 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/sigstore/rekor/rekor-server:v1.5.4100d793d68d0
google.golang.org/grpc@v1.82.1
1.83.1
ghcr.io/sigstore/scaffolding/createtreedigest-pinnede5232e8c9122
google.golang.org/grpc@v1.76.0
1.83.1
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
google.golang.org/grpc@v1.82.0
1.83.1
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

5,373
snyk-monitorsnyk2.23.261 of 2See more

snyk-monitor snyk 2.23.26

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
snyk/kubernetes-monitor:2.23.26fb5ad76ce84e
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

584
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.03 of 3See more

swo-k8s-collector solarwinds 5.3.0

3 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
google.golang.org/grpc@v1.81.1
1.83.1
ghcr.io/open-telemetry/opentelemetry-ebpf-instrumentation/ebpf-instrument:v0.9.026f82b148dfe
google.golang.org/grpc@v1.80.0
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.06b2f0b6f2f86
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

2,377
sops-operatorsops-operatorVerified publisher0.10.11 of 2See more

sops-operator sops-operator 0.10.1

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/peak-scale/sops-operator:0.10.11da9b716b792
google.golang.org/grpc@v1.82.0
1.83.1

Open the chart page →

1,257
thehivestrangebee-helmOfficialVerified publisher1.0.72 of 7See more

thehive strangebee-helm 1.0.7

2 of the 7 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
google.golang.org/grpc@v1.71.0
1.83.1
minio/minio:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
google.golang.org/grpc@v1.71.0
1.83.1

Open the chart page →

16,220
truenas-csptruenas-cspVerified publisher1.2.410 of 11See more

truenas-csp truenas-csp 1.2.4

10 of the 11 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/hpestorage/csi-driver:v3.2.0ef7f4e1544fa
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/hpestorage/csi-extensions:v1.2.1189146672a7ac
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/hpestorage/volume-group-provisioner:v1.0.107bf9d8f16a5d
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/hpestorage/volume-group-snapshotter:v1.0.10caeaaffe7e2b
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/hpestorage/volume-mutator:v1.3.109e98b2e697bd
google.golang.org/grpc@v1.79.3
1.83.1
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
google.golang.org/grpc@v1.81.1
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
google.golang.org/grpc@v1.79.1
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
google.golang.org/grpc@v1.78.0
1.83.1

Open the chart page →

5,918
uffizzi-controlleruffizzi-controller2.4.62 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

2 of the 11 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
google.golang.org/grpc@v1.60.1
1.83.1
quay.io/jetstack/cert-manager-webhook:v1.14.5ef419261a209
google.golang.org/grpc@v1.60.1
1.83.1

Open the chart page →

14,327
vsphere-csivsphere-tmm3.8.17 of 7See more

vsphere-csi vsphere-tmm 3.8.1

7 of the 7 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
registry.k8s.io/csi-vsphere/driver:v3.5.04bb8350a5a62
google.golang.org/grpc@v1.68.1
1.83.1
registry.k8s.io/csi-vsphere/syncer:v3.5.0bb88468fff2a
google.golang.org/grpc@v1.68.1
1.83.1
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
google.golang.org/grpc@v1.69.4
1.83.1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
google.golang.org/grpc@v1.69.0
1.83.1
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
google.golang.org/grpc@v1.60.0
1.83.1
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
google.golang.org/grpc@v1.69.2
1.83.1
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
google.golang.org/grpc@v1.69.0
1.83.1

Open the chart page →

3,957
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

6,177
kubedbappscodeVerified publisher2026.7.107 of 8See more

kubedb appscode 2026.7.10

7 of the 8 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/appscode/petset:v0.1.093fa0daf603c
google.golang.org/grpc@v1.72.1
1.83.1
ghcr.io/appscode/sidekick:v0.0.15d1036b07e348
google.golang.org/grpc@v1.72.1
1.83.1
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
google.golang.org/grpc@v1.79.3
1.83.1
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
google.golang.org/grpc@v1.79.3
1.83.1
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
google.golang.org/grpc@v1.79.3
1.83.1
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
google.golang.org/grpc@v1.79.3
1.83.1
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

4,145
cloudflaredartur9010Verified publisher1.0.91 of 3See more

cloudflared artur9010 1.0.9

1 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

3,008
alb-controllerazure-application-gateway-for-containers1.12.12 of 3See more

alb-controller azure-application-gateway-for-containers 1.12.1

2 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
mcr.microsoft.com/application-lb/images/alb-controller:1.12.172f33b24bc67
google.golang.org/grpc@v1.82.1
1.83.1
mcr.microsoft.com/application-lb/images/alb-controller-bootstrap:1.12.1cc129fd1c904
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

221
baserowbaserow-chartVerified publisher1.0.562 of 6See more

baserow baserow-chart 1.0.56

2 of the 6 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
google.golang.org/grpc@v1.65.0
1.83.1
caddy/ingress:v0.2.118d1366fc0e9
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

17,413
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
google.golang.org/grpc@v1.51.0
1.83.1

Open the chart page →

1,705
celestia-appcelestia-labsVerified publisher0.5.01 of 3See more

celestia-app celestia-labs 0.5.0

1 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
google.golang.org/grpc@v1.68.0
1.83.1

Open the chart page →

1,073
cert-manager-webhook-hetznercert-manager-webhook-hetznerVerified publisher0.2.11 of 1See more

cert-manager-webhook-hetzner cert-manager-webhook-hetzner 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

3,087
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
google.golang.org/grpc@v1.33.1
1.83.1
library/traefik:2.5.47d0228d19042
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

53,052
openstack-cloud-controller-managercloud-provider-openstack2.36.51 of 1See more

openstack-cloud-controller-manager cloud-provider-openstack 2.36.5

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/openstack-cloud-controller-manager:v1.36.0e354e40db2d0
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

505
cloudquerycloudquery39.0.41 of 1See more

cloudquery cloudquery 39.0.4

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/cloudquery/cloudquery:6.40.040b804fce7f9
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

551
cluster-api-operatorcluster-api-operator0.29.01 of 1See more

cluster-api-operator cluster-api-operator 0.29.0

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
registry.k8s.io/capi-operator/cluster-api-operator:v0.29.0465e72f8b06a
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

47
immudbcodenotaryVerified publisher1.9.71 of 1See more

immudb codenotary 1.9.7

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
codenotary/immudb:1.9.77c85d7cc4f22
google.golang.org/grpc@v1.57.1
1.83.1

Open the chart page →

1,254
routercosmo-routerOfficialVerified publisher0.18.01 of 1See more

router cosmo-router 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

1,686
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
wait4x/wait4x:3.3.14dcd86307de1
google.golang.org/grpc@v1.71.0
1.83.1

Open the chart page →

9,208
csi-wekafsplugincsi-wekafsOfficialVerified publisher0.6.2-01 of 6See more

csi-wekafsplugin csi-wekafs 0.6.2-0

1 of the 6 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
google.golang.org/grpc@v1.10.0
1.83.1

Open the chart page →

2,831
daskhubdask2024.1.12 of 9See more

daskhub dask 2024.1.1

2 of the 9 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
library/traefik:2.10.61957e3314f43
google.golang.org/grpc@v1.58.3
1.83.1
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
google.golang.org/grpc@v1.56.3
1.83.1

Open the chart page →

14,151
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

27,426
drone-runner-dockerdroneVerified publisher0.7.02 of 3See more

drone-runner-docker drone 0.7.0

2 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
drone/drone-runner-docker:1.8.1137e79c5e23c
google.golang.org/grpc@v1.29.1
1.83.1
library/docker:20-dindaf96c680a7e1
google.golang.org/grpc@v1.50.1
1.83.1

Open the chart page →

5,690
k8s-image-swapperestahnVerified publisher1.11.01 of 2See more

k8s-image-swapper estahn 1.11.0

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
google.golang.org/grpc@v1.59.0
1.83.1

Open the chart page →

1,987
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

1,767
flannelflannel0.28.91 of 2See more

flannel flannel 0.28.9

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/flannel-io/flannel:v0.28.9708a2c9c1cfb
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

616
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
google.golang.org/grpc@v1.41.0
1.83.1
thesisrobot/loop:v0.11.1-beta89ae07e787ca
google.golang.org/grpc@v1.24.0
1.83.1
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

8,854
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

1,745
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.22.1e8cad21b2f9a
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

2,917
alloy-operatorgrafana0.7.11 of 1See more

alloy-operator grafana 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

428
grafana-mcpgrafana-communityVerified publisher0.23.21 of 1See more

grafana-mcp grafana-community 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
grafana/mcp-grafana:1.4.2f87fa67a561f
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

1,090
klusterviewklusterviewVerified publisher0.1.02 of 4See more

klusterview klusterview 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

3,811
gateway-operatorkongOfficialVerified publisher0.6.11 of 1See more

gateway-operator kong 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
kong/gateway-operator:1.603510967482b
google.golang.org/grpc@v1.71.1
1.83.1

Open the chart page →

849
kubeflowkubeflow1.6.218 of 45See more

kubeflow kubeflow 1.6.2

18 of the 45 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
google.golang.org/grpc@v1.36.0
1.83.1
istio/proxyv2:1.14.1df69c1a7af7c
google.golang.org/grpc@v1.45.0
1.83.1
kserve/kserve-controller:v0.8.0f0692a9ea09f
google.golang.org/grpc@v1.42.0
1.83.1
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
google.golang.org/grpc@v1.42.0
1.83.1
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
google.golang.org/grpc@v1.42.0
1.83.1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
google.golang.org/grpc@v1.42.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
google.golang.org/grpc@v1.44.0
1.83.1
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
google.golang.org/grpc@v1.44.0
1.83.1
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

97,217
testkubekubeshop2.13.21 of 5See more

testkube kubeshop 2.13.2

1 of the 5 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
kubeshop/testkube-minio:2025.10d8e1af6aca99
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

5,151
openelbkubesphere-stable0.5.01 of 2See more

openelb kubesphere-stable 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

4,336
venti-stackkuossOfficialVerified publisher0.5.03 of 9See more

venti-stack kuoss 0.5.0

3 of the 9 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/prometheus/prometheus:v3.13.2508729e0e2d1
google.golang.org/grpc@v1.82.1
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

3,830
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

4,070

Container images carrying it

2,766 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
tusproject/tusd:v1.10.01e457b59fd5b
google.golang.org/grpc@v1.50.0
1.83.1
1
tusproject/tusd:v1.13.0f8088058b80f
google.golang.org/grpc@v1.57.0
1.83.1
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
google.golang.org/grpc@v1.31.0
1.83.1
1
twinproduction/gatus:v5.34.03fff895e77d3
google.golang.org/grpc@v1.77.0
1.83.1
1
tykio/portal:v1.18.092509e00e618
google.golang.org/grpc@v1.80.0
1.83.1
1
tykio/tyk-operator:v1.4.2e13d37f298b7
google.golang.org/grpc@v1.79.3
1.83.1
1
ubercadence/server:0.23.22ac5491d13bb
google.golang.org/grpc@v1.29.1
1.83.1
1
udhos/apiping:1.5.041ab9bae6f3b
google.golang.org/grpc@v1.77.0
1.83.1
1
udhos/gateboard:1.12.53acc0e7599bf
google.golang.org/grpc@v1.76.0
1.83.1
1
udhos/gateboard-discovery:1.9.55567c9363c4c
google.golang.org/grpc@v1.76.0
1.83.1
1
udhos/kubecache:0.14.1f44ef986df49
google.golang.org/grpc@v1.82.1
1.83.1
1
udhos/lambdaping:1.0.46bd2cf2ac732
google.golang.org/grpc@v1.69.2
1.83.1
1
udhos/secrets:1.0.6daa2b4eaac09
google.golang.org/grpc@v1.71.1
1.83.1
1
udhos/snsping:1.2.96ae70677b6a3
google.golang.org/grpc@v1.69.2
1.83.1
1
uptrace/uptrace:2.0.234a02c3b2d12
google.golang.org/grpc@v1.73.0
1.83.1
1
v2fly/v2fly-core:latestd06727b221fe
google.golang.org/grpc@v1.76.0
1.83.1
1
vdaas/vald-agent-ngt:v1.8.032e3695fe585
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-benchmark-operator:v1.8.006b4a9b4ab06
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-discoverer-k8s:v1.8.0f6495f38ae92
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-lb-gateway:v1.8.061009e319a9a
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-manager-index:v1.8.0ab881d2262d8
google.golang.org/grpc@v1.83.0
1.83.1
1
vdaas/vald-operator:latest0c3dcd4974f6
google.golang.org/grpc@v1.83.0
1.83.1
1
vearch/vearch:3.3.40768af33f9d9
google.golang.org/grpc@v1.26.0
1.83.1
1
veecode/devportala72cf5cb47b8
google.golang.org/grpc@v1.79.3
1.83.1
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
google.golang.org/grpc@v1.58.3
1.83.1
1
velero/velero:v1.18.111459094b1b2
google.golang.org/grpc@v1.80.0
1.83.1
1
velero/velero:v1.9.0277fbfaf8dcf
google.golang.org/grpc@v1.38.0
1.83.1
1
velero/velero:v1.18.237396519f399
google.golang.org/grpc@v1.81.1
1.83.1
1
velero/velero:v1.8.18d784580931c
google.golang.org/grpc@v1.40.0
1.83.1
1
velero/velero:v1.18.0e4d1e79be2ee
google.golang.org/grpc@v1.77.0
1.83.1
1
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
google.golang.org/grpc@v1.40.0
1.83.1
1
velero/velero-plugin-for-aws:v1.14.07e82f717f44e
google.golang.org/grpc@v1.77.0
1.83.1
1
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
google.golang.org/grpc@v1.27.0
1.83.1
1
volcanosh/vc-scheduler:v1.15.2afab36286a17
google.golang.org/grpc@v1.79.3
1.83.1
1
volcanosh/vc-scheduler:v1.12.1b24ea8af2d16
google.golang.org/grpc@v1.57.0
1.83.1
1
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
google.golang.org/grpc@v1.57.0
1.83.1
1
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
google.golang.org/grpc@v1.27.0
1.83.1
1
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
google.golang.org/grpc@v1.27.1
1.83.1
1
vultr/vultr-csi:v0.3.041d26735d437
google.golang.org/grpc@v1.40.0
1.83.1
1
wait4x/wait4x:3.3.14dcd86307de1
google.golang.org/grpc@v1.71.0
1.83.1
1
wallarm/aih-scanner:2.7.11f1cb26db1f5b
google.golang.org/grpc@v1.75.0
1.83.1
1
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
google.golang.org/grpc@v1.62.1
1.83.1
1
wallarm/node-native-processing:0.25.860828c36ee6d
google.golang.org/grpc@v1.83.0
1.83.1
1
wallarm/node-native-processing:0.23.07db2da8fce0b
google.golang.org/grpc@v1.79.1
1.83.1
1
wavefronthq/prometheus-storage-adapter:latestded77b38c7c6
google.golang.org/grpc@v1.56.3
1.83.1
1
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
google.golang.org/grpc@v1.38.0
1.83.1
1
wazuh/wazuh-manager:4.11.11da5c38c6a78
google.golang.org/grpc@v1.29.1
1.83.1
1
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/grpc@v1.29.1
1.83.1
1
wazuh/wazuh-manager:4.14.45a065930682d
google.golang.org/grpc@v1.29.1
1.83.1
1
wazuh/wazuh-manager:4.14.3f09282d281f6
google.golang.org/grpc@v1.29.1
1.83.1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.