StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,342
of 17,787 indexed, latest versions
Container images
2,841
deployed by those charts
Fix available
2 of 2
affected packages

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,342 of 17,787 indexed charts deploy, on 2,841 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,840
kubernetes-1.34apk1.34.11-r21.34.11-r81
OSV records
GHSA-2v4p-qf9q-27wjCGA-2675-68qh-x3xm
Also known as
CGA-2rc7-c9wv-rg9j, CGA-2v9r-g7hg-wjpv, CGA-5pg3-vg83-278x, CGA-6jwq-4523-qrxc, CGA-6mqf-6cj9-rr4r, CGA-8vf4-hpwm-ghh8, CGA-96jx-jhxg-fxww, CGA-fg8c-vc3x-88hf, CGA-g3hq-cpjp-v4p5, CGA-hx92-g8xp-6m86, CGA-wgvj-wq84-52gh
Trending
Rank 7 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,342 by stars
ChartLatestAffected imagesRadar Score
flannelflannel0.28.91 of 2See more

flannel flannel 0.28.9

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/flannel-io/flannel:v0.28.9708a2c9c1cfb
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

610
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
google.golang.org/grpc@v1.41.0
1.82.2
thesisrobot/loop:v0.11.1-beta89ae07e787ca
google.golang.org/grpc@v1.24.0
1.82.2
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
google.golang.org/grpc@v1.29.1
1.82.2

Open the chart page →

8,834
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
google.golang.org/grpc@v1.27.1
1.82.2

Open the chart page →

1,738
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.22.1e8cad21b2f9a
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

2,800
alloy-operatorgrafana0.7.11 of 1See more

alloy-operator grafana 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

420
grafana-mcpgrafana-communityVerified publisher0.23.21 of 1See more

grafana-mcp grafana-community 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/mcp-grafana:1.4.2f87fa67a561f
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

1,009
klusterviewklusterviewVerified publisher0.1.02 of 4See more

klusterview klusterview 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.82.2
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

3,796
gateway-operatorkongOfficialVerified publisher0.6.11 of 1See more

gateway-operator kong 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kong/gateway-operator:1.603510967482b
google.golang.org/grpc@v1.71.1
1.82.2

Open the chart page →

842
kong-meshkong-meshVerified publisher2.14.42 of 3See more

kong-mesh kong-mesh 2.14.4

2 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kong/kuma-cp:2.14.47e4f53630a28
google.golang.org/grpc@v1.83.1
1.83.2
kong/kumactl:2.14.463d11b2d3f60
google.golang.org/grpc@v1.83.1
1.83.2

Open the chart page →

529
kubeflowkubeflow1.6.218 of 45See more

kubeflow kubeflow 1.6.2

18 of the 45 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
google.golang.org/grpc@v1.36.0
1.82.2
istio/proxyv2:1.14.1df69c1a7af7c
google.golang.org/grpc@v1.45.0
1.82.2
kserve/kserve-controller:v0.8.0f0692a9ea09f
google.golang.org/grpc@v1.42.0
1.82.2
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
google.golang.org/grpc@v1.42.0
1.82.2
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
google.golang.org/grpc@v1.42.0
1.82.2
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
google.golang.org/grpc@v1.42.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
google.golang.org/grpc@v1.44.0
1.82.2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

97,040
testkubekubeshop2.13.22 of 5See more

testkube kubeshop 2.13.2

2 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kubeshop/testkube-api-server:2.13.244166c28422f
google.golang.org/grpc@v1.83.1
1.83.2
kubeshop/testkube-minio:2025.10d8e1af6aca99
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

5,012
openelbkubesphere-stable0.5.01 of 2See more

openelb kubesphere-stable 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

4,329
sbomscannerkubewardenVerified publisher0.12.13 of 5See more

sbomscanner kubewarden 0.12.1

3 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/kubewarden/sbomscanner/controller:v0.12.1153ccb651e49
google.golang.org/grpc@v1.83.1
1.83.2
ghcr.io/kubewarden/sbomscanner/storage:v0.12.1811ed0383187
google.golang.org/grpc@v1.83.1
1.83.2
ghcr.io/kubewarden/sbomscanner/worker:v0.12.1b4274b7cc473
google.golang.org/grpc@v1.83.1
1.83.2

Open the chart page →

988
venti-stackkuossOfficialVerified publisher0.5.03 of 9See more

venti-stack kuoss 0.5.0

3 of the 9 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:v3.13.2508729e0e2d1
google.golang.org/grpc@v1.82.1
1.82.2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

3,810
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

4,050
vclustermainVerified publisher0.17.06 of 10See more

vcluster main 0.17.0

6 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
google.golang.org/grpc@v1.51.0
1.82.2
registry.k8s.io/etcd:3.6.4-0e36c08168342
google.golang.org/grpc@v1.71.1
1.82.2
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
google.golang.org/grpc@v1.40.0
1.82.2
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
google.golang.org/grpc@v1.47.0
1.82.2
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
google.golang.org/grpc@v1.47.0
1.82.2
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
google.golang.org/grpc@v1.47.0
1.82.2

Open the chart page →

11,556
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
headscale/headscale:0.25.1a7a8ae9616bb
google.golang.org/grpc@v1.69.0
1.82.2

Open the chart page →

7,968
node-local-dnsnode-local-dns2.4.01 of 1See more

node-local-dns node-local-dns 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
google.golang.org/grpc@v1.56.3
1.82.2

Open the chart page →

2,601
nri-memtierdnri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-memtierd nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memtierd:v0.14.09138314e12ba
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

269
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
google.golang.org/grpc@v1.56.1
1.82.2

Open the chart page →

8,767
capsuleprojectcapsuleOfficialVerified publisher0.14.51 of 2See more

capsule projectcapsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/projectcapsule/capsule:v0.14.5e9ee63f6196c
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

1,231
proxmox-cloud-controller-managerproxmox-ccm0.2.301 of 1See more

proxmox-cloud-controller-manager proxmox-ccm 0.2.30

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-cloud-controller-manager:v0.15.0fbc553921145
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

109
rke2-multusrke2-charts3.7.1-build20210416011 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
google.golang.org/grpc@v1.23.0
1.82.2

Open the chart page →

4,519
fulciosigstoreVerified publisher2.11.14 of 6See more

fulcio sigstore 2.11.1

4 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/sigstore/fulcio:v1.8.8ef72cf56c64b
google.golang.org/grpc@v1.81.1
1.82.2
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
google.golang.org/grpc@v1.76.0
1.82.2
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
google.golang.org/grpc@v1.76.0
1.82.2
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
google.golang.org/grpc@v1.76.0
1.82.2

Open the chart page →

3,491
policy-controllersigstoreVerified publisher0.10.81 of 2See more

policy-controller sigstore 0.10.8

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
google.golang.org/grpc@v1.71.1
1.82.2

Open the chart page →

911
pubsubplus-hasolaceVerified publisher3.10.01 of 1See more

pubsubplus-ha solace 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
solace/solace-pubsub-standard:latest8e8ad105595e
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

264
sops-secrets-operatorsops-secrets-operatorVerified publisher0.28.11 of 1See more

sops-secrets-operator sops-secrets-operator 0.28.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

820
steampipe-powerpipe-kubernetessteampipe-powerpipe-kubernetesVerified publisher0.13.12 of 2See more

steampipe-powerpipe-kubernetes steampipe-powerpipe-kubernetes 0.13.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
google.golang.org/grpc@v1.79.3
1.82.2
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

5,493
topolvmtopolvmVerified publisher17.2.01 of 1See more

topolvm topolvm 17.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
google.golang.org/grpc@v1.78.0
1.82.2

Open the chart page →

2,364
uffizzi-appuffizzi-app1.3.03 of 14See more

uffizzi-app uffizzi-app 1.3.0

3 of the 14 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
google.golang.org/grpc@v1.58.3
1.82.2
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
google.golang.org/grpc@v1.58.3
1.82.2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
google.golang.org/grpc@v1.58.3
1.82.2

Open the chart page →

19,363
valdvald1.8.04 of 5See more

vald vald 1.8.0

4 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
vdaas/vald-agent-ngt:v1.8.032e3695fe585
google.golang.org/grpc@v1.83.0
1.83.2
vdaas/vald-discoverer-k8s:v1.8.0f6495f38ae92
google.golang.org/grpc@v1.83.0
1.83.2
vdaas/vald-lb-gateway:v1.8.061009e319a9a
google.golang.org/grpc@v1.83.0
1.83.2
vdaas/vald-manager-index:v1.8.0ab881d2262d8
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

188
vault-operatorvault-operatorVerified publisher1.24.01 of 1See more

vault-operator vault-operator 1.24.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-operator:v1.24.06f622c5fb8a9
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

535
vault-secrets-webhookvault-secrets-webhookVerified publisher1.23.11 of 1See more

vault-secrets-webhook vault-secrets-webhook 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-secrets-webhook:v1.23.198baf045a1c9
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

519
athens-proxyvolker-raschekVerified publisher2.0.31 of 1See more

athens-proxy volker-raschek 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
gomods/athens:v0.17.10f61d1e62359
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

2,040
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

13,567
yunikornyunikornVerified publisher1.9.02 of 3See more

yunikorn yunikorn 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
apache/yunikorn:scheduler-1.9.096832082e9cf
google.golang.org/grpc@v1.79.3
1.82.2
apache/yunikorn:admission-1.9.0fe8f5ec91f6c
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

398
aperture-controlleraperture2.34.02 of 5See more

aperture-controller aperture 2.34.0

2 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
fluxninja/aperture-operator:2.34.0356d7aa86632
google.golang.org/grpc@v1.60.1
1.82.2
quay.io/prometheus/prometheus:v2.33.591100b06e86d
google.golang.org/grpc@v1.43.0
1.82.2

Open the chart page →

4,663
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
google.golang.org/grpc@v1.38.0
1.82.2

Open the chart page →

3,300
athens-proxyathens-chartsOfficialVerified publisher0.17.11 of 1See more

athens-proxy athens-charts 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
gomods/athens:v0.18.197cc113b34b0
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

1,299
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
google.golang.org/grpc@v1.38.0
1.82.2

Open the chart page →

9,052
prometheusaveshaVerified publisher19.3.01 of 4See more

prometheus avesha 19.3.0

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
google.golang.org/grpc@v1.51.0
1.82.2

Open the chart page →

5,484
snapschedulerbackube-helm-chartsVerified publisher3.5.01 of 2See more

snapscheduler backube-helm-charts 3.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
google.golang.org/grpc@v1.65.0
1.82.2

Open the chart page →

1,224
boundaryboundaryVerified publisher0.1.01 of 1See more

boundary boundary 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/boundary:0.21.037bf86488b74
google.golang.org/grpc@v1.76.0
1.82.2

Open the chart page →

1,438
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
google.golang.org/grpc@v1.59.0
1.82.2

Open the chart page →

1,884
cert-managerchoerodon1.8.23 of 4See more

cert-manager choerodon 1.8.2

3 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
google.golang.org/grpc@v1.43.0
1.82.2
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
google.golang.org/grpc@v1.43.0
1.82.2
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
google.golang.org/grpc@v1.43.0
1.82.2

Open the chart page →

7,775
sbom-operatorckotzbauerVerified publisher0.46.21 of 1See more

sbom-operator ckotzbauer 0.46.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/sbom-operator:0.45.2dbdb3e524dea
google.golang.org/grpc@v1.83.1
1.83.2

Open the chart page →

40
cloudprobercloudproberOfficialVerified publisher1.14.251 of 1See more

cloudprober cloudprober 1.14.25

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cloudprober/cloudprober:v0.14.540c6d960ae4f
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

212
dumpscriptcloudscriptVerified publisher1.8.31 of 1See more

dumpscript cloudscript 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
google.golang.org/grpc@v1.76.0
1.82.2

Open the chart page →

2,126
cluster-manager-servercluster-manager-server1.8.01 of 1See more

cluster-manager-server cluster-manager-server 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
google.golang.org/grpc@v1.68.1
1.82.2

Open the chart page →

746
coder-observabilitycoder-observabilityVerified publisher0.7.38 of 21See more

coder-observability coder-observability 0.7.3

8 of the 21 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
burningalchemist/sql_exporter:latest2586aa37f140
google.golang.org/grpc@v1.83.1
1.83.2
grafana/agent:v0.40.3f6cbec9409be
google.golang.org/grpc@v1.61.0
1.82.2
grafana/grafana:10.4.19a9043254ba16
google.golang.org/grpc@v1.71.0
1.82.2
grafana/loki:3.1.0d947e68a84d9
google.golang.org/grpc@v1.62.1
1.82.2
grafana/loki-canary:3.1.039baf6d67f85
google.golang.org/grpc@v1.62.1
1.82.2
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
google.golang.org/grpc@v1.44.0
1.82.2
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
google.golang.org/grpc@v1.49.0
1.82.2
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
google.golang.org/grpc@v1.64.0
1.82.2

Open the chart page →

24,698

Container images carrying it

2,841 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
google.golang.org/grpc@v1.53.0
1.82.2
1
dongjiang1989/pingmesh-agent:latest355fa4be8e97
google.golang.org/grpc@v1.67.0
1.82.2
1
dongjiang1989/pingmesh-agent:v1.2.2c82de0272da0
google.golang.org/grpc@v1.67.0
1.82.2
1
dragonflyoss/client:v1.5.4a1b52779c4dd
google.golang.org/grpc@v1.81.1
1.82.2
1
dragonflyoss/client:v0.1.82edf3e921f4e0
google.golang.org/grpc@v1.60.1
1.82.2
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
google.golang.org/grpc@v1.64.0
1.82.2
1
dragonflyoss/scheduler:v2.1.49523785c77787
google.golang.org/grpc@v1.64.0
1.82.2
1
dragonflyoss/scheduler:v2.5.2-rc.06d710dc2bae0
google.golang.org/grpc@v1.79.3
1.82.2
1
drone/drone:2.28.255897c8fb22d
google.golang.org/grpc@v1.59.0
1.82.2
1
drone/drone-runner-docker:1.8.1137e79c5e23c
google.golang.org/grpc@v1.29.1
1.82.2
1
drumsergio/duplicacy-container:0.1.0dd3ee9703969
google.golang.org/grpc@v1.28.1
1.82.2
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/grpc@v1.49.0
1.82.2
1
dunglas/mercure:v0.24.080fcb704a741
google.golang.org/grpc@v1.81.0
1.82.2
1
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
google.golang.org/grpc@v1.56.3
1.82.2
1
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
google.golang.org/grpc@v1.40.0
1.82.2
1
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
google.golang.org/grpc@v1.27.0
1.82.2
1
eginnovations/agent:7.5.4e4dfe242fe9f
google.golang.org/grpc@v1.80.0
1.82.2
1
eginnovations/universal-agent-operator:0.0.11b8e3e26dca1b
google.golang.org/grpc@v1.68.1
1.82.2
1
elastic/apm-server:7.17.6c7a1c63257d0
google.golang.org/grpc@v1.48.0
1.82.2
1
elastiflow/flow-collector:7.26.0fee67842e16b
google.golang.org/grpc@v1.81.0
1.82.2
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
google.golang.org/grpc@v1.82.1
1.82.2
1
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
google.golang.org/grpc@v1.68.1
1.82.2
1
emqx/ecp-main:2.5.1fa876f71e5d6
google.golang.org/grpc@v1.67.1
1.82.2
1
emqxecp/otelcol:2.5.04c31d9bec846
google.golang.org/grpc@v1.66.0
1.82.2
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
google.golang.org/grpc@v1.31.0
1.82.2
1
envoyproxy/ai-gateway-controller:003ab39f36923b5d40609a601e2951b73f6318fbec1f06ee29a7
google.golang.org/grpc@v1.74.2
1.82.2
1
envoyproxy/gateway:v1.9.10049bcb384c5
google.golang.org/grpc@v1.83.1
1.83.2
1
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/grpc@v1.56.2
1.82.2
1
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
google.golang.org/grpc@v1.65.0
1.82.2
1
envoyproxy/ratelimit:v1.4.071081616da3e
google.golang.org/grpc@v1.19.0
1.82.2
1
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
google.golang.org/grpc@v1.27.0
1.82.2
1
envoyproxy/ratelimit:4d2efd61ede09a75a84c
google.golang.org/grpc@v1.27.0
1.82.2
1
epamedp/edp-headlamp:0.25.093417e18bb1a
google.golang.org/grpc@v1.60.1
1.82.2
1
epamedp/edp-tekton:0.2.4924939850655
google.golang.org/grpc@v1.50.1
1.82.2
1
epamedp/keycloak-operator:1.35.0a5398eaa7b80
google.golang.org/grpc@v1.79.3
1.82.2
1
epamedp/nexus-operator:3.6.09fede333ef27
google.golang.org/grpc@v1.82.1
1.82.2
1
epamedp/sonar-operator:3.4.0661d1648a49a
google.golang.org/grpc@v1.82.1
1.82.2
1
epamedp/tekton-custom-task:0.2.067d896676f45
google.golang.org/grpc@v1.70.0
1.82.2
1
erigontech/erigon:latest2252efdf9abe
google.golang.org/grpc@v1.83.0
1.83.2
1
erigontech/erigon:v2.61.288706754b627
google.golang.org/grpc@v1.63.2
1.82.2
1
ethereum/client-go:latest37575ec10fbc
google.golang.org/grpc@v1.79.1
1.82.2
1
ethereum/client-go:stableb8ab3451a117
google.golang.org/grpc@v1.79.1
1.82.2
1
ethpandaops/cbt-api:latest9dc0b50e6c27
google.golang.org/grpc@v1.80.0
1.82.2
1
ethpandaops/clickhouse-movoor:latestc0e6cc6542c1
google.golang.org/grpc@v1.81.1
1.82.2
1
ethpandaops/contributoor:latest1edd4074fd79
google.golang.org/grpc@v1.80.0
1.82.2
1
ethpandaops/forky:debian-latestc937f4ba737c
google.golang.org/grpc@v1.72.1
1.82.2
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
google.golang.org/grpc@v1.74.2
1.82.2
1
ethpandaops/xatu-cbt-api:latestf7dec2e07091
google.golang.org/grpc@v1.76.0
1.82.2
1
evcc/evcc:0.300.8ddf2a25afce5
google.golang.org/grpc@v1.78.0
1.82.2
1
factly/mande-server:0.34.1384d384310ef
google.golang.org/grpc@v1.50.1
1.82.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.