StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,370
of 17,821 indexed, latest versions
Container images
2,838
deployed by those charts
Fix available
1 of 1
affected package

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,370 of 17,821 indexed charts deploy, on 2,838 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,838
OSV records
GHSA-2v4p-qf9q-27wj
Also known as
GO-2026-6443
Trending
Rank 42 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,370 by stars
ChartLatestAffected imagesRadar Score
jaegerwikimedia3.1.23 of 4See more

jaeger wikimedia 3.1.2

3 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
google.golang.org/grpc@v1.60.0
1.82.2
jaegertracing/jaeger-collector:1.53.07f1269222903
google.golang.org/grpc@v1.60.0
1.82.2
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
google.golang.org/grpc@v1.60.0
1.82.2

Open the chart page →

9,364
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
google.golang.org/grpc@v1.56.1
1.82.2

Open the chart page →

2,035
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
google.golang.org/grpc@v1.30.0
1.82.2

Open the chart page →

2,753
csi-driver-host-pathwiremindVerified publisher0.1.18 of 8See more

csi-driver-host-path wiremind 0.1.1

8 of the 8 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
google.golang.org/grpc@v1.47.0
1.82.2
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
google.golang.org/grpc@v1.48.0
1.82.2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
google.golang.org/grpc@v1.50.1
1.82.2
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
google.golang.org/grpc@v1.49.0
1.82.2
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
google.golang.org/grpc@v1.47.0
1.82.2
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
google.golang.org/grpc@v1.47.0
1.82.2
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
google.golang.org/grpc@v1.34.0
1.82.2
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
google.golang.org/grpc@v1.48.0
1.82.2

Open the chart page →

12,666
orcwiremindVerified publisher0.3.01 of 1See more

orc wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/orc/openstack-resource-controller:v2.5.079f22af49612
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

277
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
google.golang.org/grpc@v1.68.0
1.82.2

Open the chart page →

1,358
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,513
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,624
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.82.2

Open the chart page →

1,061
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

13,925
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
google.golang.org/grpc@v1.72.2
1.82.2

Open the chart page →

402
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.82.2

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

4,928
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.82.2

Open the chart page →

9,743
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.82.2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.82.2

Open the chart page →

9,528
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.82.2

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.82.2
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.82.2
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.82.2
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.82.2

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.82.2
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.82.2
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

5,077

Container images carrying it

2,838 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/grafana:7.5.609bb407e26ab
google.golang.org/grpc@v1.36.0
1.82.2
1
grafana/grafana:7.3.315b977f5207d
google.golang.org/grpc@v1.30.0
1.82.2
1
grafana/grafana:9.4.71a359d92f40e
google.golang.org/grpc@v1.45.0
1.82.2
1
grafana/grafana:10.1.11b9ca4bbc4a2
google.golang.org/grpc@v1.45.0
1.82.2
1
grafana/grafana:13.0.1-security-012d1f9ae67c17
google.golang.org/grpc@v1.79.3
1.82.2
1
grafana/grafana:12.2.22ebef928d7e5
google.golang.org/grpc@v1.74.2
1.82.2
1
grafana/grafana:12.2.135c41e0fd029
google.golang.org/grpc@v1.74.2
1.82.2
1
grafana/grafana:9.5.239c849cebccc
google.golang.org/grpc@v1.45.0
1.82.2
1
grafana/grafana:11.2.2-security-01464eac539793
google.golang.org/grpc@v1.65.0
1.82.2
1
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.82.2
1
grafana/grafana:11.6.062d2b9d20a19
google.golang.org/grpc@v1.70.0
1.82.2
1
grafana/grafana:8.0.3696823fbc561
google.golang.org/grpc@v1.37.1
1.82.2
1
grafana/grafana:10.2.36b5b37eb35bb
google.golang.org/grpc@v1.59.0
1.82.2
1
grafana/grafana:7.3.46d42886b3ebe
google.golang.org/grpc@v1.30.0
1.82.2
1
grafana/grafana:12.3.070d9599b186c
google.golang.org/grpc@v1.76.0
1.82.2
1
grafana/grafana:7.2.1733842cca5bd
google.golang.org/grpc@v1.30.0
1.82.2
1
grafana/grafana:12.2.074144189b384
google.golang.org/grpc@v1.74.2
1.82.2
1
grafana/grafana:9.4.376dcf36e7d2a
google.golang.org/grpc@v1.45.0
1.82.2
1
grafana/grafana:10.3.38640e5038e83
google.golang.org/grpc@v1.60.1
1.82.2
1
grafana/grafana:11.5.28b37a2f028f1
google.golang.org/grpc@v1.69.2
1.82.2
1
grafana/grafana:9.1.19746858c20e6
google.golang.org/grpc@v1.45.0
1.82.2
1
grafana/grafana:12.1.1a1701c218024
google.golang.org/grpc@v1.73.0
1.82.2
1
grafana/grafana:9.0.1a738d0744784
google.golang.org/grpc@v1.45.0
1.82.2
1
grafana/grafana:10.4.19a9043254ba16
google.golang.org/grpc@v1.71.0
1.82.2
1
grafana/grafana:13.1.3ab5cb380e3ff
google.golang.org/grpc@v1.82.1
1.82.2
1
grafana/grafana:11.1.3b23b588cf7cb
google.golang.org/grpc@v1.64.0
1.82.2
1
grafana/grafana:12.0.2b5b59bfc7561
google.golang.org/grpc@v1.72.1
1.82.2
1
grafana/grafana:8.1.5b7dd9cd0e59d
google.golang.org/grpc@v1.39.0
1.82.2
1
grafana/grafana:12.3.2ba93c9d192e5
google.golang.org/grpc@v1.77.0
1.82.2
1
grafana/grafana:6.5.1befcd84da2c1
google.golang.org/grpc@v1.23.1
1.82.2
1
grafana/grafana:8.3.5cd7cb4345aa7
google.golang.org/grpc@v1.41.0
1.82.2
1
grafana/grafana:8.3.4cf81d2c753c8
google.golang.org/grpc@v1.41.0
1.82.2
1
grafana/grafana:7.4.5d322192ed2fa
google.golang.org/grpc@v1.35.0
1.82.2
1
grafana/grafana:9.3.6e5a9655dabef
google.golang.org/grpc@v1.45.0
1.82.2
1
grafana/grafana:8.5.3ecc1b80b8ca2
google.golang.org/grpc@v1.42.0
1.82.2
1
grafana/grafana:10.4.0f9811e4e687f
google.golang.org/grpc@v1.60.1
1.82.2
1
grafana/grafana:11.3.1fa801ab6e1ae
google.golang.org/grpc@v1.66.0
1.82.2
1
grafana/logcli:main-c90366d-amd643d85bb66e39b
google.golang.org/grpc@v1.37.0
1.82.2
1
grafana/loki:2.9.1035b02acc6765
google.golang.org/grpc@v1.56.3
1.82.2
1
grafana/loki:2.9.26074e01dbe03
google.golang.org/grpc@v1.56.3
1.82.2
1
grafana/loki:2.9.66ca6e2cd3b6f
google.golang.org/grpc@v1.56.3
1.82.2
1
grafana/loki:3.0.0757b5fadf816
google.golang.org/grpc@v1.62.1
1.82.2
1
grafana/loki:2.0.077e138f81a8e
google.golang.org/grpc@v1.29.1
1.82.2
1
grafana/loki:3.7.487f0a0676737
google.golang.org/grpc@v1.81.1
1.82.2
1
grafana/loki:3.2.0882e30c20683
google.golang.org/grpc@v1.65.0
1.82.2
1
grafana/loki:3.3.28af2de1abbdd
google.golang.org/grpc@v1.67.1
1.82.2
1
grafana/loki:3.6.192bd5700577b
google.golang.org/grpc@v1.75.1
1.82.2
1
grafana/loki:2.8.2b1da1d23037e
google.golang.org/grpc@v1.52.3
1.82.2
1
grafana/loki:2.4.2b3af8ead67d7
google.golang.org/grpc@v1.40.0
1.82.2
1
grafana/loki:3.6.3cd6e176883a9
google.golang.org/grpc@v1.75.1
1.82.2
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.