StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,342
of 17,787 indexed, latest versions
Container images
2,841
deployed by those charts
Fix available
2 of 2
affected packages

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,342 of 17,787 indexed charts deploy, on 2,841 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,840
kubernetes-1.34apk1.34.11-r21.34.11-r81
OSV records
GHSA-2v4p-qf9q-27wjCGA-2675-68qh-x3xm
Also known as
CGA-2rc7-c9wv-rg9j, CGA-2v9r-g7hg-wjpv, CGA-5pg3-vg83-278x, CGA-6jwq-4523-qrxc, CGA-6mqf-6cj9-rr4r, CGA-8vf4-hpwm-ghh8, CGA-96jx-jhxg-fxww, CGA-fg8c-vc3x-88hf, CGA-g3hq-cpjp-v4p5, CGA-hx92-g8xp-6m86, CGA-wgvj-wq84-52gh
Trending
Rank 7 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,342 by stars
ChartLatestAffected imagesRadar Score
flannelflannel0.28.91 of 2See more

flannel flannel 0.28.9

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/flannel-io/flannel:v0.28.9708a2c9c1cfb
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

610
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
google.golang.org/grpc@v1.41.0
1.82.2
thesisrobot/loop:v0.11.1-beta89ae07e787ca
google.golang.org/grpc@v1.24.0
1.82.2
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
google.golang.org/grpc@v1.29.1
1.82.2

Open the chart page →

8,834
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
google.golang.org/grpc@v1.27.1
1.82.2

Open the chart page →

1,738
gitops-promotergitops-promoterOfficialVerified publisher0.17.01 of 2See more

gitops-promoter gitops-promoter 0.17.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.22.1e8cad21b2f9a
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

2,800
alloy-operatorgrafana0.7.11 of 1See more

alloy-operator grafana 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

420
grafana-mcpgrafana-communityVerified publisher0.23.21 of 1See more

grafana-mcp grafana-community 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/mcp-grafana:1.4.2f87fa67a561f
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

1,009
klusterviewklusterviewVerified publisher0.1.02 of 4See more

klusterview klusterview 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.82.2
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

3,796
gateway-operatorkongOfficialVerified publisher0.6.11 of 1See more

gateway-operator kong 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kong/gateway-operator:1.603510967482b
google.golang.org/grpc@v1.71.1
1.82.2

Open the chart page →

842
kong-meshkong-meshVerified publisher2.14.42 of 3See more

kong-mesh kong-mesh 2.14.4

2 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kong/kuma-cp:2.14.47e4f53630a28
google.golang.org/grpc@v1.83.1
1.83.2
kong/kumactl:2.14.463d11b2d3f60
google.golang.org/grpc@v1.83.1
1.83.2

Open the chart page →

529
kubeflowkubeflow1.6.218 of 45See more

kubeflow kubeflow 1.6.2

18 of the 45 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
google.golang.org/grpc@v1.36.0
1.82.2
istio/proxyv2:1.14.1df69c1a7af7c
google.golang.org/grpc@v1.45.0
1.82.2
kserve/kserve-controller:v0.8.0f0692a9ea09f
google.golang.org/grpc@v1.42.0
1.82.2
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
google.golang.org/grpc@v1.42.0
1.82.2
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
google.golang.org/grpc@v1.42.0
1.82.2
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
google.golang.org/grpc@v1.42.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
google.golang.org/grpc@v1.44.0
1.82.2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

97,040
testkubekubeshop2.13.22 of 5See more

testkube kubeshop 2.13.2

2 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kubeshop/testkube-api-server:2.13.244166c28422f
google.golang.org/grpc@v1.83.1
1.83.2
kubeshop/testkube-minio:2025.10d8e1af6aca99
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

5,012
openelbkubesphere-stable0.5.01 of 2See more

openelb kubesphere-stable 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

4,329
sbomscannerkubewardenVerified publisher0.12.13 of 5See more

sbomscanner kubewarden 0.12.1

3 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/kubewarden/sbomscanner/controller:v0.12.1153ccb651e49
google.golang.org/grpc@v1.83.1
1.83.2
ghcr.io/kubewarden/sbomscanner/storage:v0.12.1811ed0383187
google.golang.org/grpc@v1.83.1
1.83.2
ghcr.io/kubewarden/sbomscanner/worker:v0.12.1b4274b7cc473
google.golang.org/grpc@v1.83.1
1.83.2

Open the chart page →

988
venti-stackkuossOfficialVerified publisher0.5.03 of 9See more

venti-stack kuoss 0.5.0

3 of the 9 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:v3.13.2508729e0e2d1
google.golang.org/grpc@v1.82.1
1.82.2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

3,810
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

4,050
vclustermainVerified publisher0.17.06 of 10See more

vcluster main 0.17.0

6 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
google.golang.org/grpc@v1.51.0
1.82.2
registry.k8s.io/etcd:3.6.4-0e36c08168342
google.golang.org/grpc@v1.71.1
1.82.2
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
google.golang.org/grpc@v1.40.0
1.82.2
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
google.golang.org/grpc@v1.47.0
1.82.2
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
google.golang.org/grpc@v1.47.0
1.82.2
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
google.golang.org/grpc@v1.47.0
1.82.2

Open the chart page →

11,556
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
headscale/headscale:0.25.1a7a8ae9616bb
google.golang.org/grpc@v1.69.0
1.82.2

Open the chart page →

7,968
node-local-dnsnode-local-dns2.4.01 of 1See more

node-local-dns node-local-dns 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
google.golang.org/grpc@v1.56.3
1.82.2

Open the chart page →

2,601
nri-memtierdnri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-memtierd nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memtierd:v0.14.09138314e12ba
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

269
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
google.golang.org/grpc@v1.56.1
1.82.2

Open the chart page →

8,767
capsuleprojectcapsuleOfficialVerified publisher0.14.51 of 2See more

capsule projectcapsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/projectcapsule/capsule:v0.14.5e9ee63f6196c
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

1,231
proxmox-cloud-controller-managerproxmox-ccm0.2.301 of 1See more

proxmox-cloud-controller-manager proxmox-ccm 0.2.30

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-cloud-controller-manager:v0.15.0fbc553921145
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

109
rke2-multusrke2-charts3.7.1-build20210416011 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
google.golang.org/grpc@v1.23.0
1.82.2

Open the chart page →

4,519
fulciosigstoreVerified publisher2.11.14 of 6See more

fulcio sigstore 2.11.1

4 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/sigstore/fulcio:v1.8.8ef72cf56c64b
google.golang.org/grpc@v1.81.1
1.82.2
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
google.golang.org/grpc@v1.76.0
1.82.2
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
google.golang.org/grpc@v1.76.0
1.82.2
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
google.golang.org/grpc@v1.76.0
1.82.2

Open the chart page →

3,491
policy-controllersigstoreVerified publisher0.10.81 of 2See more

policy-controller sigstore 0.10.8

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
google.golang.org/grpc@v1.71.1
1.82.2

Open the chart page →

911
pubsubplus-hasolaceVerified publisher3.10.01 of 1See more

pubsubplus-ha solace 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
solace/solace-pubsub-standard:latest8e8ad105595e
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

264
sops-secrets-operatorsops-secrets-operatorVerified publisher0.28.11 of 1See more

sops-secrets-operator sops-secrets-operator 0.28.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

820
steampipe-powerpipe-kubernetessteampipe-powerpipe-kubernetesVerified publisher0.13.12 of 2See more

steampipe-powerpipe-kubernetes steampipe-powerpipe-kubernetes 0.13.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
google.golang.org/grpc@v1.79.3
1.82.2
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

5,493
topolvmtopolvmVerified publisher17.2.01 of 1See more

topolvm topolvm 17.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
google.golang.org/grpc@v1.78.0
1.82.2

Open the chart page →

2,364
uffizzi-appuffizzi-app1.3.03 of 14See more

uffizzi-app uffizzi-app 1.3.0

3 of the 14 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
google.golang.org/grpc@v1.58.3
1.82.2
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
google.golang.org/grpc@v1.58.3
1.82.2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
google.golang.org/grpc@v1.58.3
1.82.2

Open the chart page →

19,363
valdvald1.8.04 of 5See more

vald vald 1.8.0

4 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
vdaas/vald-agent-ngt:v1.8.032e3695fe585
google.golang.org/grpc@v1.83.0
1.83.2
vdaas/vald-discoverer-k8s:v1.8.0f6495f38ae92
google.golang.org/grpc@v1.83.0
1.83.2
vdaas/vald-lb-gateway:v1.8.061009e319a9a
google.golang.org/grpc@v1.83.0
1.83.2
vdaas/vald-manager-index:v1.8.0ab881d2262d8
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

188
vault-operatorvault-operatorVerified publisher1.24.01 of 1See more

vault-operator vault-operator 1.24.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-operator:v1.24.06f622c5fb8a9
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

535
vault-secrets-webhookvault-secrets-webhookVerified publisher1.23.11 of 1See more

vault-secrets-webhook vault-secrets-webhook 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-secrets-webhook:v1.23.198baf045a1c9
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

519
athens-proxyvolker-raschekVerified publisher2.0.31 of 1See more

athens-proxy volker-raschek 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
gomods/athens:v0.17.10f61d1e62359
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

2,040
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

13,567
yunikornyunikornVerified publisher1.9.02 of 3See more

yunikorn yunikorn 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
apache/yunikorn:scheduler-1.9.096832082e9cf
google.golang.org/grpc@v1.79.3
1.82.2
apache/yunikorn:admission-1.9.0fe8f5ec91f6c
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

398
aperture-controlleraperture2.34.02 of 5See more

aperture-controller aperture 2.34.0

2 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
fluxninja/aperture-operator:2.34.0356d7aa86632
google.golang.org/grpc@v1.60.1
1.82.2
quay.io/prometheus/prometheus:v2.33.591100b06e86d
google.golang.org/grpc@v1.43.0
1.82.2

Open the chart page →

4,663
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
google.golang.org/grpc@v1.38.0
1.82.2

Open the chart page →

3,300
athens-proxyathens-chartsOfficialVerified publisher0.17.11 of 1See more

athens-proxy athens-charts 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
gomods/athens:v0.18.197cc113b34b0
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

1,299
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
google.golang.org/grpc@v1.38.0
1.82.2

Open the chart page →

9,052
prometheusaveshaVerified publisher19.3.01 of 4See more

prometheus avesha 19.3.0

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
google.golang.org/grpc@v1.51.0
1.82.2

Open the chart page →

5,484
snapschedulerbackube-helm-chartsVerified publisher3.5.01 of 2See more

snapscheduler backube-helm-charts 3.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
google.golang.org/grpc@v1.65.0
1.82.2

Open the chart page →

1,224
boundaryboundaryVerified publisher0.1.01 of 1See more

boundary boundary 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/boundary:0.21.037bf86488b74
google.golang.org/grpc@v1.76.0
1.82.2

Open the chart page →

1,438
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
google.golang.org/grpc@v1.59.0
1.82.2

Open the chart page →

1,884
cert-managerchoerodon1.8.23 of 4See more

cert-manager choerodon 1.8.2

3 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
google.golang.org/grpc@v1.43.0
1.82.2
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
google.golang.org/grpc@v1.43.0
1.82.2
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
google.golang.org/grpc@v1.43.0
1.82.2

Open the chart page →

7,775
sbom-operatorckotzbauerVerified publisher0.46.21 of 1See more

sbom-operator ckotzbauer 0.46.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/sbom-operator:0.45.2dbdb3e524dea
google.golang.org/grpc@v1.83.1
1.83.2

Open the chart page →

40
cloudprobercloudproberOfficialVerified publisher1.14.251 of 1See more

cloudprober cloudprober 1.14.25

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cloudprober/cloudprober:v0.14.540c6d960ae4f
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

212
dumpscriptcloudscriptVerified publisher1.8.31 of 1See more

dumpscript cloudscript 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
google.golang.org/grpc@v1.76.0
1.82.2

Open the chart page →

2,126
cluster-manager-servercluster-manager-server1.8.01 of 1See more

cluster-manager-server cluster-manager-server 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
google.golang.org/grpc@v1.68.1
1.82.2

Open the chart page →

746
coder-observabilitycoder-observabilityVerified publisher0.7.38 of 21See more

coder-observability coder-observability 0.7.3

8 of the 21 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
burningalchemist/sql_exporter:latest2586aa37f140
google.golang.org/grpc@v1.83.1
1.83.2
grafana/agent:v0.40.3f6cbec9409be
google.golang.org/grpc@v1.61.0
1.82.2
grafana/grafana:10.4.19a9043254ba16
google.golang.org/grpc@v1.71.0
1.82.2
grafana/loki:3.1.0d947e68a84d9
google.golang.org/grpc@v1.62.1
1.82.2
grafana/loki-canary:3.1.039baf6d67f85
google.golang.org/grpc@v1.62.1
1.82.2
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
google.golang.org/grpc@v1.44.0
1.82.2
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
google.golang.org/grpc@v1.49.0
1.82.2
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
google.golang.org/grpc@v1.64.0
1.82.2

Open the chart page →

24,698

Container images carrying it

2,841 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hashicorp/vault-secrets-operator:1.5.1458c842add32
google.golang.org/grpc@v1.83.0
1.83.2
1
hashicorp/waypoint:0.11.397d521a27498
google.golang.org/grpc@v1.50.1
1.82.2
1
hauler/hauler:2.1.04671f9bb6c5a
google.golang.org/grpc@v1.82.1
1.82.2
1
hazelcast/hazelcast-platform-operator:5.19.02783cd66846d
google.golang.org/grpc@v1.82.1
1.82.2
1
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
google.golang.org/grpc@v1.27.0
1.82.2
1
headscale/headscale:0.25.1a7a8ae9616bb
google.golang.org/grpc@v1.69.0
1.82.2
1
headscale/headscale:0.27.1cd37b3001857
google.golang.org/grpc@v1.75.1
1.82.2
1
hetzner/cert-manager-webhook-hetzner:v0.9.0b64db89ba4c1
google.golang.org/grpc@v1.82.1
1.82.2
1
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
google.golang.org/grpc@v1.51.0
1.82.2
1
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
google.golang.org/grpc@v1.40.0
1.82.2
1
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
google.golang.org/grpc@v1.33.0
1.82.2
1
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
google.golang.org/grpc@v1.33.0
1.82.2
1
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
google.golang.org/grpc@v1.52.0
1.82.2
1
hiversh/antigravity:0.1.45-microvm0e36d98402bc
google.golang.org/grpc@v1.80.0
1.82.2
1
hiversh/browser:0.1.45-microvmb5048c6342ce
google.golang.org/grpc@v1.80.0
1.82.2
1
hiversh/claude:0.1.45-microvm2fbf9f264498
google.golang.org/grpc@v1.80.0
1.82.2
1
hiversh/codex:0.1.45-microvm4f43130f51e5
google.golang.org/grpc@v1.80.0
1.82.2
1
hiversh/controller:0.1.45b0b85f8942c7
google.golang.org/grpc@v1.80.0
1.82.2
1
hiversh/copilot:0.1.45-microvm50c07b84f298
google.golang.org/grpc@v1.80.0
1.82.2
1
hiversh/node:0.1.45-alpine-microvm836a37641941
google.golang.org/grpc@v1.80.0
1.82.2
1
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
google.golang.org/grpc@v1.80.0
1.82.2
1
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
google.golang.org/grpc@v1.80.0
1.82.2
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
google.golang.org/grpc@v1.39.0
1.82.2
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
google.golang.org/grpc@v1.59.0
1.82.2
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
google.golang.org/grpc@v1.82.1
1.82.2
1
huacnlee/gobackup:v3.1.1560be93229a5
google.golang.org/grpc@v1.59.0
1.82.2
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
google.golang.org/grpc@v1.49.0
1.82.2
1
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
google.golang.org/grpc@v1.41.0
1.82.2
1
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
google.golang.org/grpc@v1.26.0
1.82.2
1
hyperledger/fabric-ca:1.5.0f270dfeee91d
google.golang.org/grpc@v1.26.0
1.82.2
1
hyperledger/fabric-orderer:2.2.137294e05209b
google.golang.org/grpc@v1.29.1
1.82.2
1
hyperledger/fabric-peer:2.2.1bf4995c86af6
google.golang.org/grpc@v1.29.1
1.82.2
1
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
google.golang.org/grpc@v1.53.0
1.82.2
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
google.golang.org/grpc@v1.53.0
1.82.2
1
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
google.golang.org/grpc@v1.29.1
1.82.2
1
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
google.golang.org/grpc@v1.50.1
1.82.2
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
google.golang.org/grpc@v1.52.3
1.82.2
1
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
google.golang.org/grpc@v1.51.0
1.82.2
1
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
google.golang.org/grpc@v1.51.0
1.82.2
1
inaccel/cloud-init:latesta5d3d0af05c1
google.golang.org/grpc@v1.60.1
1.82.2
1
inaccel/device-selector:latest44b4f274f40b
google.golang.org/grpc@v1.61.0
1.82.2
1
infisical/cli:0.43.1230941c1293b77
google.golang.org/grpc@v1.82.1
1.82.2
1
infisical/infisical-csi-provider:v0.0.9e3390e677db6
google.golang.org/grpc@v1.64.1
1.82.2
1
infisical/kubernetes-operator:v0.11.9769ad1630a13
google.golang.org/grpc@v1.79.3
1.82.2
1
infisical/pki-issuer:latestff38294270e3
google.golang.org/grpc@v1.79.3
1.82.2
1
inseefrlab/shelly:cloudshell31f04ca7436b
google.golang.org/grpc@v1.33.1
1.82.2
1
instill/api-gateway:9bfdc88b53eaa51c523
google.golang.org/grpc@v1.71.0
1.82.2
1
instill/artifact-backend:b28766ac4a393e601ed
google.golang.org/grpc@v1.61.0
1.82.2
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
google.golang.org/grpc@v1.73.0
1.82.2
1
instill/model-backend:611f0f2e980125e5ba5
google.golang.org/grpc@v1.73.0
1.82.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.