StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,310
of 17,803 indexed, latest versions
Container images
2,803
deployed by those charts
Fix available
1 of 1
affected package

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,310 of 17,803 indexed charts deploy, on 2,803 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,803
OSV records
GHSA-2v4p-qf9q-27wj
Also known as
GO-2026-6443
Trending
Rank 10 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,310 by stars
ChartLatestAffected imagesRadar Score
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,513
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,623
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.82.2

Open the chart page →

1,060
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

13,875
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
google.golang.org/grpc@v1.72.2
1.82.2

Open the chart page →

402
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.82.2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.82.2

Open the chart page →

9,426
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.82.2

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.82.2
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.82.2
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.82.2
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.82.2

Open the chart page →

8,000
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.82.2
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.82.2
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

5,076

Container images carrying it

2,803 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
google.golang.org/grpc@v1.61.0
1.82.2
1
linode/linode-blockstorage-csi-driver:v1.1.409f3282bf53d
google.golang.org/grpc@v1.80.0
1.82.2
1
linode/linode-cloud-controller-manager:v0.9.8cd8c17512206
google.golang.org/grpc@v1.82.1
1.82.2
1
linuxserver/cloud9:latest45c5fe102ff3
google.golang.org/grpc@v1.43.0
1.82.2
1
linuxserver/wireguard:latestbf03578ef731
google.golang.org/grpc@v1.77.0
1.82.2
1
linuxserver/wireguard:1.0.20260223-r0-ls122dca67384e3e9
google.golang.org/grpc@v1.77.0
1.82.2
1
litestream/litestream:0.3c5a1e1b01916
google.golang.org/grpc@v1.57.0
1.82.2
1
livekit/ingress:v1.2.21ab01641b366
google.golang.org/grpc@v1.60.1
1.82.2
1
livekit/livekit-recorder:v0.3.13ecf1409c75e0
google.golang.org/grpc@v1.42.0
1.82.2
1
livekit/livekit-server:v1.9.03602a85840d5
google.golang.org/grpc@v1.72.2
1.82.2
1
livekit/livekit-server:v1.0.08391fd1b834f
google.golang.org/grpc@v1.42.0
1.82.2
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
google.golang.org/grpc@v1.27.1
1.82.2
1
loftsh/virtual-cluster:0.0.28023b13bf5898
google.golang.org/grpc@v1.27.1
1.82.2
1
logiqai/flash:v3.10.265b996bc7bdc
google.golang.org/grpc@v1.62.1
1.82.2
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
google.golang.org/grpc@v1.29.1
1.82.2
1
logiqai/logiqctl:2.0.4798306811f2d
google.golang.org/grpc@v1.32.0
1.82.2
1
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
google.golang.org/grpc@v1.46.2
1.82.2
1
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
google.golang.org/grpc@v1.46.2
1.82.2
1
lokxy/lokxy:v0.9.0e4ac800dc55d
google.golang.org/grpc@v1.81.1
1.82.2
1
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
google.golang.org/grpc@v1.75.1
1.82.2
1
longhornio/longhorn-manager:v1.2.3dca34321452c
google.golang.org/grpc@v1.26.0
1.82.2
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
google.golang.org/grpc@v1.23.0
1.82.2
1
longhornio/longhorn-manager:v1.12.0fd245bae2e82
google.golang.org/grpc@v1.81.1
1.82.2
1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
google.golang.org/grpc@v1.75.1
1.82.2
1
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
google.golang.org/grpc@v1.80.0
1.82.2
1
lotest/locust-k8s-operator:2.3.1859b0d36f371
google.golang.org/grpc@v1.82.1
1.82.2
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
google.golang.org/grpc@v1.72.2
1.82.2
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
google.golang.org/grpc@v1.51.0
1.82.2
1
louislam/uptime-kuma:13d632903e6af
google.golang.org/grpc@v1.72.2
1.82.2
1
louislam/uptime-kuma:2.0.24c364ef96aad
google.golang.org/grpc@v1.72.2
1.82.2
1
louislam/uptime-kuma:2.4.091e963bfda56
google.golang.org/grpc@v1.79.2
1.82.2
1
louislam/uptime-kuma:1.23.1396510915e6be
google.golang.org/grpc@v1.60.0
1.82.2
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
google.golang.org/grpc@v1.72.2
1.82.2
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
google.golang.org/grpc@v1.45.0
1.82.2
1
louislam/uptime-kuma:1.18.5a84767d7934f
google.golang.org/grpc@v1.45.0
1.82.2
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
google.golang.org/grpc@v1.60.0
1.82.2
1
lumenvox/admin-portal:7.112310cf52f79
google.golang.org/grpc@v1.80.0
1.82.2
1
lumenvox/archive:7.15114f08ab8ef
google.golang.org/grpc@v1.80.0
1.82.2
1
lumenvox/cloud-license:2.0.09a69862e1248
google.golang.org/grpc@v1.39.1
1.82.2
1
lumenvox/configuration:7.182bf01d9ebec
google.golang.org/grpc@v1.80.0
1.82.2
1
lumenvox/deployment:7.1dadac2a74be6
google.golang.org/grpc@v1.80.0
1.82.2
1
lumenvox/deployment-portal:7.19d83efc340cf
google.golang.org/grpc@v1.81.1
1.82.2
1
lumenvox/file-store:7.138aa8711c9ef
google.golang.org/grpc@v1.80.0
1.82.2
1
lumenvox/license:7.135d0b1ac053e
google.golang.org/grpc@v1.80.0
1.82.2
1
lumenvox/management-api:7.16420a6e7d6c2
google.golang.org/grpc@v1.80.0
1.82.2
1
lumenvox/resource:7.193fd6ff1d62c
google.golang.org/grpc@v1.80.0
1.82.2
1
lumenvox/storage:7.1c961fe78e2ca
google.golang.org/grpc@v1.80.0
1.82.2
1
machines/filestash:latest0b8fc005e52e
google.golang.org/grpc@v1.80.0
1.82.2
1
mantlenetworkio/l2geth:v0.4.36bf383d14291
google.golang.org/grpc@v1.55.0
1.82.2
1
maponyacharles/sceptreai:seaweedfs-0.1.127c8a525f08e9
google.golang.org/grpc@v1.82.1
1.82.2
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.