StackRadar

CVE-2026-84304

High

Advisory

Published 1 Sept 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,288
of 17,790 indexed, latest versions
Container images
2,766
deployed by those charts
Fix available
2 of 3
affected packages

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

Carried by container images the latest versions of 2,288 of 17,790 indexed charts deploy, on 2,766 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+115 more1.83.12,761
grpcdeb1.16.1-1ubuntu5, 1.51.1-4.1build5no fix listed4
kubernetes-1.34apk1.34.11-r21.34.11-r61
OSV records
CGA-2w5g-qvhw-4526GHSA-vp52-pcj8-j9qcUBUNTU-CVE-2026-84304
Also known as
CGA-2w99-fmrr-7c59, CGA-37h3-vm4r-h6gp, CGA-4rmw-5272-crfm, CGA-8mvv-qrfc-pwm2, CGA-94hq-vh86-c5h5, CGA-9c5q-7vcp-52g3, CGA-j2mp-r3h6-gw3j, CGA-j357-xxg6-gx2j, CGA-w54h-8g59-4jxp, CGA-wj6g-63h9-g67r, CGA-xmw7-6f5r-33jj, GO-2026-6348
Trending
Rank 35 in indexed charts, since 5 Sept 2026. See the ranking →

Charts affected

2,288 by stars
ChartLatestAffected imagesRadar Score
thanosrayselfs-chartsVerified publisher0.1.51 of 1See more

thanos rayselfs-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.40.1aae7b2b030ed
google.golang.org/grpc@v1.73.0
1.83.1

Open the chart page →

757
saleorrc-helm-charts0.1.11 of 5See more

saleor rc-helm-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.22.0ca6b73330616
google.golang.org/grpc@v1.29.1
1.83.1

Open the chart page →

3,745
reactive-policyreactive-policy0.4.11 of 1See more

reactive-policy reactive-policy 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/vedooo/reactive-policy:0.4.1d92eda891c91
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

77
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

15,299
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

15,299
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

11,446
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
google.golang.org/grpc@v1.33.2
1.83.1

Open the chart page →

29,564
longhornrelease-longhorn1.12.02 of 3See more

longhorn release-longhorn 1.12.0

2 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.12.0fd245bae2e82
google.golang.org/grpc@v1.81.1
1.83.1
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
google.golang.org/grpc@v1.80.0
1.83.1

Open the chart page →

1,579
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
reportportal/migrations:5.7.0da5d8e1395fe
google.golang.org/grpc@v1.20.1
1.83.1

Open the chart page →

25,756
restic-pvc-backuprestic-pvc-backupVerified publisher0.2.12 of 2See more

restic-pvc-backup restic-pvc-backup 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ngosang/restic-exporter:2.1.2a8f9cfa30162
google.golang.org/grpc@v1.81.1
1.83.1
restic/restic:0.19.1136600b6ff68
google.golang.org/grpc@v1.81.1
1.83.1

Open the chart page →

954
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

7,116
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

7,501
istio-fortiorgnu1.0.31 of 1See more

istio-fortio rgnu 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
fortio/fortio:latest_releasefc8221136fe2
google.golang.org/grpc@v1.72.1
1.83.1

Open the chart page →

547
harvester-cloud-providerrke2-charts0.2.15002 of 2See more

harvester-cloud-provider rke2-charts 0.2.1500

2 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rancher/harvester-cloud-provider:v0.2.8199961f11ba6
google.golang.org/grpc@v1.82.1
1.83.1
rancher/mirrored-kube-vip-kube-vip-iptables:v1.2.389c3f898ac5a
google.golang.org/grpc@v1.83.0
1.83.1

Open the chart page →

452
harvester-csi-driverrke2-charts0.1.31006 of 6See more

harvester-csi-driver rke2-charts 0.1.3100

6 of the 6 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rancher/harvester-csi-driver:v0.2.9f9099b5ef8cb
google.golang.org/grpc@v1.79.3
1.83.1
rancher/mirrored-longhornio-csi-attacher:v4.11.0-20260428fe417c28a6b8
google.golang.org/grpc@v1.79.3
1.83.1
rancher/mirrored-longhornio-csi-node-driver-registrar:v2.16.0-20260428e82a8c8f800d
google.golang.org/grpc@v1.79.3
1.83.1
rancher/mirrored-longhornio-csi-provisioner:v5.3.0-202604289e519a21a77c
google.golang.org/grpc@v1.79.3
1.83.1
rancher/mirrored-longhornio-csi-resizer:v2.1.0-2026042841cb674d1154
google.golang.org/grpc@v1.79.3
1.83.1
rancher/mirrored-longhornio-csi-snapshotter:v8.5.0-202604281975fac3890f
google.golang.org/grpc@v1.79.3
1.83.1

Open the chart page →

2,729
rancher-vsphere-cpirke2-charts1.16.2001 of 1See more

rancher-vsphere-cpi rke2-charts 1.16.200

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rancher/mirrored-cloud-provider-vsphere:v1.31.1febfd0517838
google.golang.org/grpc@v1.65.0
1.83.1

Open the chart page →

912
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022022 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

2 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
google.golang.org/grpc@v1.19.0
1.83.1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
google.golang.org/grpc@v1.27.0
1.83.1

Open the chart page →

5,956
rke2-ciliumrke2-charts1.20.1032 of 3See more

rke2-cilium rke2-charts 1.20.103

2 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
google.golang.org/grpc@v1.82.1
1.83.1
quay.io/cilium/operator-generic:v1.20.16c3885fc7b62
google.golang.org/grpc@v1.82.1
1.83.1

Open the chart page →

1,092
memosrm3lVerified publisher0.1.11 of 1See more

memos rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
neosmemo/memos:0.24c6defc2dfb98
google.golang.org/grpc@v1.72.2
1.83.1

Open the chart page →

1,622
ntfyrm3lVerified publisher0.1.11 of 1See more

ntfy rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
google.golang.org/grpc@v1.63.2
1.83.1

Open the chart page →

1,283
olivetinrm3lVerified publisher0.2.01 of 1See more

olivetin rm3l 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
google.golang.org/grpc@v1.69.2
1.83.1

Open the chart page →

1,377
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
google.golang.org/grpc@v1.49.0
1.83.1

Open the chart page →

4,047
fleet-vendoredrock8sVerified publisher6.5.11 of 1See more

fleet-vendored rock8s 6.5.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
fleetdm/fleet:v4.66.012e644b7f40e
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

1,588
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

5,430
imgproxyrock8sVerified publisher0.8.301 of 1See more

imgproxy rock8s 0.8.30

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.15.040f6eb807444
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

2,029
mailserverrock8sVerified publisher0.1.21 of 1See more

mailserver rock8s 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
google.golang.org/grpc@v1.54.0
1.83.1

Open the chart page →

1,954
monitoringrocketchat-server0.0.173 of 9See more

monitoring rocketchat-server 0.0.17

3 of the 9 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
grafana/loki:3.6.3cd6e176883a9
google.golang.org/grpc@v1.75.1
1.83.1
otel/opentelemetry-collector-contrib:0.143.03bc07732530c
google.golang.org/grpc@v1.78.0
1.83.1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.16.0e750cd4b43f7
google.golang.org/grpc@v1.68.1
1.83.1

Open the chart page →

6,884
jaegerromanow-helm-chartsVerified publisher1.7.31 of 1See more

jaeger romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.9.0e128b9adbb29
google.golang.org/grpc@v1.74.2
1.83.1

Open the chart page →

1,605
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
google.golang.org/grpc@v1.64.0
1.83.1

Open the chart page →

9,685
argocdromholdings1.8.12 of 3See more

argocd romholdings 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/grpc@v1.15.0
1.83.1
quay.io/dexidp/dex:v2.25.07bcf286807b8
google.golang.org/grpc@v1.26.0
1.83.1

Open the chart page →

10,484
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

13,011
argo-workflowromholdings0.1.61 of 1See more

argo-workflow romholdings 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

1,587
caddy-reverse-proxyromholdings0.10.11 of 1See more

caddy-reverse-proxy romholdings 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
library/caddy:latestdf7f1c2fb114
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

853
calicoromholdings0.1.13 of 4See more

calico romholdings 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/grpc@v1.27.1
1.83.1

Open the chart page →

10,094
devtron-enterpriseromholdings48.0.014 of 28See more

devtron-enterprise romholdings 48.0.0

14 of the 28 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.83.1
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.83.1
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/grpc@v1.27.1
1.83.1
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.83.1
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.83.1
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
google.golang.org/grpc@v1.67.1
1.83.1

Open the chart page →

68,695
devtron-in-clustercdromholdings0.10.22 of 2See more

devtron-in-clustercd romholdings 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/grpc@v1.33.1
1.83.1
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/grpc@v1.53.0
1.83.1

Open the chart page →

5,055
devtron-operatorromholdings0.23.37 of 11See more

devtron-operator romholdings 0.23.3

7 of the 11 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.83.1
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.83.1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.83.1
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
google.golang.org/grpc@v1.79.3
1.83.1
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.83.1

Open the chart page →

33,180
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/grpc@v1.20.1
1.83.1

Open the chart page →

11,959
kube-prometheus-stackromholdings19.3.02 of 6See more

kube-prometheus-stack romholdings 19.3.0

2 of the 6 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/grpc@v1.40.0
1.83.1
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/grpc@v1.38.0
1.83.1

Open the chart page →

8,659
migrantromholdings0.0.31 of 1See more

migrant romholdings 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
migrate/migrate:latestcc4ad8e19d66
google.golang.org/grpc@v1.74.2
1.83.1

Open the chart page →

740
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/grpc@v1.43.0
1.83.1

Open the chart page →

2,441
zincromholdings0.1.21 of 1See more

zinc romholdings 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/grpc@v1.41.0
1.83.1

Open the chart page →

1,514
controllerrookout0.2.561 of 1See more

controller rookout 0.2.56

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
google.golang.org/grpc@v1.57.0
1.83.1

Open the chart page →

1,967
datastorerookout0.1.481 of 1See more

datastore rookout 0.1.48

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rookout/data-on-prem:latest51c0fce64467
google.golang.org/grpc@v1.57.0
1.83.1

Open the chart page →

1,948
rookout-hybridrookout0.3.12 of 2See more

rookout-hybrid rookout 0.3.1

2 of the 2 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
google.golang.org/grpc@v1.57.0
1.83.1
rookout/data-on-prem:latest51c0fce64467
google.golang.org/grpc@v1.57.0
1.83.1

Open the chart page →

3,915
acme-linoderotationalVerified publisher1.0.41 of 1See more

acme-linode rotational 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rotationalio/linode-acme-webhook:1.0.0cc7bb030a20f
google.golang.org/grpc@v1.75.1
1.83.1

Open the chart page →

1,316
beaconrotationalVerified publisher0.2.01 of 1See more

beacon rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rotationalio/beacon:0.2.0f8d8b694515a
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

968
geopingrotationalVerified publisher1.3.21 of 1See more

geoping rotational 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rotationalio/geoping:1.3.034bcb6fc3cb7
google.golang.org/grpc@v1.79.2
1.83.1

Open the chart page →

1,592
rotational-apirotationalVerified publisher1.3.11 of 1See more

rotational-api rotational 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
rotationalio/rotational-api:1.3.0f1a2d05d8fff
google.golang.org/grpc@v1.79.2
1.83.1

Open the chart page →

1,590
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84304.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
google.golang.org/grpc@v1.81.0
1.83.1

Open the chart page →

7,527

Container images carrying it

2,766 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/prometheus:latest:v3.14.05ce7540c3c00
google.golang.org/grpc@v1.82.1
1.83.1
18
minio/minio:latest:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
google.golang.org/grpc@v1.71.0
1.83.1
16
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.83.1
12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
google.golang.org/grpc@v1.75.1
1.83.1
12
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
google.golang.org/grpc@v1.81.1
1.83.1
12
ethpandaops/xatu:latest74d4cf2c436c
google.golang.org/grpc@v1.80.0
1.83.1
10
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
google.golang.org/grpc@v1.81.1
1.83.1
10
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.20.042cfe3723a5f
google.golang.org/grpc@v1.79.3
1.83.1
9
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
google.golang.org/grpc@v1.69.0
1.83.1
8
quay.io/prometheus/alertmanager:latest:v0.34.0690c7b525f43
google.golang.org/grpc@v1.82.1
1.83.1
8
wurstmeister/kafka:latest2d4bbf9cc83d
google.golang.org/grpc@v1.44.0
1.83.1
7
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
google.golang.org/grpc@v1.69.2
1.83.1
7
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
google.golang.org/grpc@v1.67.1
1.83.1
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
google.golang.org/grpc@v1.63.2
1.83.1
7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.83.1
7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
google.golang.org/grpc@v1.72.1
1.83.1
7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
google.golang.org/grpc@v1.78.0
1.83.1
7
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.83.1
7
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
google.golang.org/grpc@v1.69.2
1.83.1
7
grafana/grafana:7.0.3d72946c8e5d5
google.golang.org/grpc@v1.27.1
1.83.1
6
minio/mc:latest:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
google.golang.org/grpc@v1.71.0
1.83.1
6
ghcr.io/quenchworks/images/grafana3ccc56791c8a
google.golang.org/grpc@v1.82.1
1.83.1
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.83.1
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.83.1
6
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.83.1
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.83.1
6
registry.k8s.io/sig-storage/csi-attacher:v4.12.0b9dc9a714a48
google.golang.org/grpc@v1.81.1
1.83.1
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
google.golang.org/grpc@v1.54.0
1.83.1
6
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
google.golang.org/grpc@v1.72.1
1.83.1
6
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
google.golang.org/grpc@v1.81.1
1.83.1
6
keelhq/keel:latest73714afb4443
google.golang.org/grpc@v1.68.0
1.83.1
5
prom/prometheus:v2.13.10a8caa2e9f19
google.golang.org/grpc@v1.22.1
1.83.1
5
traefik/whoami:latest:v1.12.0c4717a8d1f01
google.golang.org/grpc@v1.82.1
1.83.1
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
google.golang.org/grpc@v1.65.0
1.83.1
5
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
google.golang.org/grpc@v1.10.0
1.83.1
5
quay.io/prometheus/blackbox-exporter:latest:v0.28.0e753ff9f3fc4
google.golang.org/grpc@v1.77.0
1.83.1
5
registry.k8s.io/sig-storage/csi-attacher:v4.11.0b74b05b39501
google.golang.org/grpc@v1.72.2
1.83.1
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/grpc@v1.36.0
1.83.1
5
registry.k8s.io/sig-storage/csi-provisioner:v6.2.06be9f63ca4ca
google.golang.org/grpc@v1.79.1
1.83.1
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/grpc@v1.54.0
1.83.1
5
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
google.golang.org/grpc@v1.79.3
1.83.1
5
registry.k8s.io/sig-storage/csi-resizer:v2.2.1ea1d25e23479
google.golang.org/grpc@v1.79.3
1.83.1
5
registry.k8s.io/sig-storage/csi-snapshotter:v8.6.042af0929bcd6
google.golang.org/grpc@v1.81.1
1.83.1
5
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
google.golang.org/grpc@v1.78.0
1.83.1
5
cloudflare/cloudflared:2026.3.06b599ca3e974
google.golang.org/grpc@v1.72.2
1.83.1
4
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
google.golang.org/grpc@v1.36.0
1.83.1
4
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
google.golang.org/grpc@v1.36.0
1.83.1
4
grafana/grafana:13.1.0121a7a9ece6d
google.golang.org/grpc@v1.79.3
1.83.1
4
grafana/grafana:6.7.11ff3999e0fc0
google.golang.org/grpc@v1.23.1
1.83.1
4
grafana/grafana:13.2.2-distroless69a5d2d957ca
google.golang.org/grpc@v1.81.1
1.83.1
4

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.