StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,322
of 17,792 indexed, latest versions
Container images
2,815
deployed by those charts
Fix available
2 of 2
affected packages

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,322 of 17,792 indexed charts deploy, on 2,815 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,814
kubernetes-1.34apk1.34.11-r21.34.11-r81
OSV records
GHSA-2v4p-qf9q-27wjCGA-2675-68qh-x3xm
Also known as
CGA-2rc7-c9wv-rg9j, CGA-2v9r-g7hg-wjpv, CGA-5pg3-vg83-278x, CGA-6jwq-4523-qrxc, CGA-6mqf-6cj9-rr4r, CGA-8vf4-hpwm-ghh8, CGA-96jx-jhxg-fxww, CGA-fg8c-vc3x-88hf, CGA-g3hq-cpjp-v4p5, CGA-hx92-g8xp-6m86, CGA-wgvj-wq84-52gh, GO-2026-6443
Trending
Rank 7 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,322 by stars
ChartLatestAffected imagesRadar Score
electric-mailcryptexlabsVerified publisher0.0.11 of 5See more

electric-mail cryptexlabs 0.0.1

1 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/grpc@v1.29.1
1.82.2

Open the chart page →

5,980
purple-piecryptexlabsVerified publisher0.0.11 of 4See more

purple-pie cryptexlabs 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/grpc@v1.29.1
1.82.2

Open the chart page →

5,980
agent-sandboxcsghubVerified publisher0.5.61 of 1See more

agent-sandbox csghub 0.5.6

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.6dc23fb0d5624
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

37
csghubcsghubVerified publisher2.5.015 of 34See more

csghub csghub 2.5.0

15 of the 34 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
google.golang.org/grpc@v1.79.3
1.82.2
envoyproxy/gateway:v1.7.5156b7d32c73b
google.golang.org/grpc@v1.82.0
1.82.2
grafana/loki:3.4.258a6c186ce78
google.golang.org/grpc@v1.70.0
1.82.2
opencsghq/csghub-server:v2.5.0-ee587046575c2c
google.golang.org/grpc@v1.82.1
1.82.2
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
google.golang.org/grpc@v1.71.0
1.82.2
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
google.golang.org/grpc@v1.67.1
1.82.2
opencsghq/gitlab-shell:v19.2.580a65ac370da
google.golang.org/grpc@v1.80.0
1.82.2
opencsghq/kube-state-metrics:v2.19.15ea147562ec8
google.golang.org/grpc@v1.79.3
1.82.2
opencsghq/lws:v0.6.1de15437db41b
google.golang.org/grpc@v1.65.0
1.82.2
opencsghq/prometheus:v3.13.00aac0d04749e
google.golang.org/grpc@v1.81.1
1.82.2
gcr.io/knative-releases/knative.dev/operator/cmd/operator:v1.22.3733f21dc06f9
google.golang.org/grpc@v1.80.0
1.82.2
gcr.io/knative-releases/knative.dev/operator/cmd/webhook:v1.22.366ae76179a80
google.golang.org/grpc@v1.80.0
1.82.2
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
google.golang.org/grpc@v1.72.2
1.82.2
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
google.golang.org/grpc@v1.72.2
1.82.2
registry.k8s.io/agent-sandbox/agent-sandbox-controller:v0.5.4be477ba317d8
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

49,244
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
casbin/casdoor:3.62.17729da148c61
google.golang.org/grpc@v1.79.3
1.82.2
envoyproxy/gateway:v1.7.5156b7d32c73b
google.golang.org/grpc@v1.82.0
1.82.2

Open the chart page →

11,573
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.7.5156b7d32c73b
google.golang.org/grpc@v1.82.0
1.82.2

Open the chart page →

6,768
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

15,397
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/grpc@v1.29.1
1.82.2

Open the chart page →

13,973
csi-driver-ipfscsi-driver-ipfs0.2.06 of 6See more

csi-driver-ipfs csi-driver-ipfs 0.2.0

6 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
google.golang.org/grpc@v1.81.1
1.82.2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0ab482308a492
google.golang.org/grpc@v1.78.0
1.82.2
registry.k8s.io/sig-storage/csi-provisioner:v6.1.1d992c36d4ddd
google.golang.org/grpc@v1.75.1
1.82.2
registry.k8s.io/sig-storage/csi-resizer:v2.1.0589e525cddef
google.golang.org/grpc@v1.78.0
1.82.2
registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0da081c27e8a6
google.golang.org/grpc@v1.78.0
1.82.2
registry.k8s.io/sig-storage/livenessprobe:v2.18.0c4cc074199c0
google.golang.org/grpc@v1.78.0
1.82.2

Open the chart page →

3,668
ipfs-clustercsi-driver-ipfs0.2.02 of 2See more

ipfs-cluster csi-driver-ipfs 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:v1.1.6a83266c524f1
google.golang.org/grpc@v1.81.0
1.82.2
ipfs/kubo:v0.41.00661819c2e09
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

1,496
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

1,239
cw-container-insightcwci0.7.01 of 1See more

cw-container-insight cwci 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:latest-arm649dea6643715a
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

280
cloudflaredcyberjakeVerified publisher0.3.201 of 1See more

cloudflared cyberjake 0.3.20

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.6.16d91c121b803
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

625
irods-csi-drivercyverse0.12.04 of 4See more

irods-csi-driver cyverse 0.12.0

4 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
cyverse/irods-csi-driver:v0.12.0aa69d105b292
google.golang.org/grpc@v1.81.0
1.82.2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
google.golang.org/grpc@v1.59.0
1.82.2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/grpc@v1.40.0
1.82.2
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
google.golang.org/grpc@v1.58.0
1.82.2

Open the chart page →

5,295
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
google.golang.org/grpc@v1.65.0
1.82.2
registry.k8s.io/kube-scheduler:v1.28.1146cf7475c8da
google.golang.org/grpc@v1.56.3
1.82.2

Open the chart page →

16,732
miniod4nVerified publisher5.2.12 of 2See more

minio d4n 5.2.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-04-29T09-56-05Zc574fac67f60
google.golang.org/grpc@v1.63.2
1.82.2
quay.io/minio/minio:RELEASE.2024-06-04T19-20-08Zc6b68f158628
google.golang.org/grpc@v1.63.2
1.82.2

Open the chart page →

2,659
cloudflareddamounVerified publisher3.3.01 of 1See more

cloudflared damoun 3.3.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.5.05d5f70a59d5e
google.golang.org/grpc@v1.63.0
1.82.2

Open the chart page →

1,313
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
google.golang.org/grpc@v1.41.0
1.82.2

Open the chart page →

3,247
dapr-agentsdapr-agents-devVerified publisher0.1.515 of 31See more

dapr-agents dapr-agents-dev 0.1.5

15 of the 31 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:12.3.39e1e77ade304
google.golang.org/grpc@v1.78.0
1.82.2
grafana/loki:3.6.5847c287ada0e
google.golang.org/grpc@v1.75.1
1.82.2
grafana/loki-canary:3.6.5fbb984bab741
google.golang.org/grpc@v1.75.1
1.82.2
grafana/tempo:2.9.065a578975943
google.golang.org/grpc@v1.75.0
1.82.2
mcp/grafana:latest9362bcf6aa0e
google.golang.org/grpc@v1.80.0
1.82.2
otel/opentelemetry-collector-contrib:0.145.0a7343f018690
google.golang.org/grpc@v1.78.0
1.82.2
ghcr.io/dapr/injector:1.17.0-rc.37a2fd888ed5f
google.golang.org/grpc@v1.73.0
1.82.2
ghcr.io/dapr/operator:1.17.0-rc.3d5cc61cbe735
google.golang.org/grpc@v1.73.0
1.82.2
ghcr.io/dapr/placement:1.17.0-rc.3a237b43cd5c6
google.golang.org/grpc@v1.73.0
1.82.2
ghcr.io/dapr/scheduler:1.17.0-rc.36c62e01e736b
google.golang.org/grpc@v1.73.0
1.82.2
ghcr.io/dapr/sentry:1.17.0-rc.3bf79b03591e0
google.golang.org/grpc@v1.73.0
1.82.2
ghcr.io/kagent-dev/kagent/tools:0.0.13c8882543f693
google.golang.org/grpc@v1.76.0
1.82.2
ghcr.io/kagent-dev/kmcp/controller:0.2.283276357d448
google.golang.org/grpc@v1.65.0
1.82.2
public.ecr.aws/diagrid-dev/diagrid-dashboard:latestf1348a65664a
google.golang.org/grpc@v1.80.0
1.82.2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.18.01545919b72e3
google.golang.org/grpc@v1.75.1
1.82.2

Open the chart page →

22,370
dns-mesh-controllerdashdns2.0.81 of 2See more

dns-mesh-controller dashdns 2.0.8

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
emirozbir/dashdns-controller:v2.0.5d3a5c1063425
google.golang.org/grpc@v1.68.1
1.82.2

Open the chart page →

1,103
dasherdasher0.1.11 of 1See more

dasher dasher 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/flohansen/dasher-server:latest7cde8c3fa2d1
google.golang.org/grpc@v1.64.0
1.82.2

Open the chart page →

1,096
dask-gatewaydask2026.3.01 of 2See more

dask-gateway dask 2026.3.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
library/traefik:3.3.5104204dadedf
google.golang.org/grpc@v1.67.1
1.82.2

Open the chart page →

2,002
cloudwatch-agent-prometheusdasmeta0.2.21 of 1See more

cloudwatch-agent-prometheus dasmeta 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
google.golang.org/grpc@v1.28.0
1.82.2

Open the chart page →

2,985
spqr-routerdasmeta0.1.11 of 1See more

spqr-router dasmeta 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
pgsharding/spqr-router:nightly-2.8.3-1839-f66048d84734940216d3
google.golang.org/grpc@v1.77.0
1.82.2

Open the chart page →

687
adot-exporter-for-eks-on-ec2dasmeta-adot0.15.51 of 1See more

adot-exporter-for-eks-on-ec2 dasmeta-adot 0.15.5

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
google.golang.org/grpc@v1.53.0
1.82.2

Open the chart page →

1,933
monitoring-stackdata354-helmVerified publisher1.4.23 of 4See more

monitoring-stack data354-helm 1.4.2

3 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.82.2
grafana/loki:latestd70e4659623f
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

3,227
datadog-csi-driverdatadogVerified publisher0.17.02 of 2See more

datadog-csi-driver datadog 0.17.0

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
gcr.io/datadoghq/csi-driver:1.4.086c713de81d9
google.golang.org/grpc@v1.83.0
1.83.2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,055
agent-helmdatasaker0.1.85 of 6See more

agent-helm datasaker 0.1.8

5 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
datasaker/dsk-container-agent:latest08b52999f67b
google.golang.org/grpc@v1.57.0
1.82.2
datasaker/dsk-k8s-agent:latest2542ee73be51
google.golang.org/grpc@v1.50.1
1.82.2
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
google.golang.org/grpc@v1.58.3
1.82.2
datasaker/dsk-node-agent:latest1b95913b6729
google.golang.org/grpc@v1.58.3
1.82.2
datasaker/dsk-process-agent:latest2f38720a637d
google.golang.org/grpc@v1.58.3
1.82.2

Open the chart page →

7,606
ambassador-agentdatawire1.0.221 of 1See more

ambassador-agent datawire 1.0.22

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ambassador/ambassador-agent:1.0.227a1ea0d934fb
google.golang.org/grpc@v1.59.0
1.82.2

Open the chart page →

965
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
google.golang.org/grpc@v1.24.0
1.82.2

Open the chart page →

7,495
eg-edge-stackdatawire0.0.13 of 7See more

eg-edge-stack datawire 0.0.1

3 of the 7 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
google.golang.org/grpc@v1.56.2
1.82.2
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
google.golang.org/grpc@v1.56.2
1.82.2
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/grpc@v1.56.2
1.82.2

Open the chart page →

15,882
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
defactops/defactops-ui:1.0.16825cdf9ba706
google.golang.org/grpc@v1.62.1
1.82.2

Open the chart page →

4,547
csi-driver-smbdeimosfr-charts1.20.35 of 5See more

csi-driver-smb deimosfr-charts 1.20.3

5 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0f9de845b1701
google.golang.org/grpc@v1.81.1
1.82.2
registry.k8s.io/sig-storage/csi-provisioner:v6.3.0a4b0b1a37605
google.golang.org/grpc@v1.81.1
1.82.2
registry.k8s.io/sig-storage/csi-resizer:v2.2.0a2d40c1c3ccb
google.golang.org/grpc@v1.79.3
1.82.2
registry.k8s.io/sig-storage/livenessprobe:v2.19.006da0d5b8908
google.golang.org/grpc@v1.81.1
1.82.2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

2,985
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
google.golang.org/grpc@v1.45.0
1.82.2

Open the chart page →

2,241
k8s-cloudwatch-adapterdeliveryheroVerified publisher0.2.21 of 1See more

k8s-cloudwatch-adapter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
google.golang.org/grpc@v1.23.1
1.82.2

Open the chart page →

2,475
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
google.golang.org/grpc@v1.46.0
1.82.2
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
google.golang.org/grpc@v1.46.0
1.82.2

Open the chart page →

4,736
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
google.golang.org/grpc@v1.64.0
1.82.2

Open the chart page →

9,703
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/grpc@v1.15.0
1.82.2
quay.io/dexidp/dex:v2.25.07bcf286807b8
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

10,484
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/grpc@v1.43.0
1.82.2

Open the chart page →

13,033
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/grpc@v1.53.0
1.82.2

Open the chart page →

1,587
caddy-reverse-proxydevtron0.10.11 of 1See more

caddy-reverse-proxy devtron 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
library/caddy:latest13ba145cba2f
google.golang.org/grpc@v1.81.0
1.82.2

Open the chart page →

846
devtron-enterprisedevtron48.0.014 of 28See more

devtron-enterprise devtron 48.0.0

14 of the 28 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/grpc@v1.36.1
1.82.2
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
google.golang.org/grpc@v1.79.3
1.82.2
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
google.golang.org/grpc@v1.79.3
1.82.2
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
google.golang.org/grpc@v1.79.3
1.82.2
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/grpc@v1.34.0
1.82.2
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
google.golang.org/grpc@v1.79.3
1.82.2
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/grpc@v1.79.3
1.82.2
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/grpc@v1.27.1
1.82.2
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/grpc@v1.47.0
1.82.2
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
google.golang.org/grpc@v1.79.3
1.82.2
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
google.golang.org/grpc@v1.79.3
1.82.2
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
google.golang.org/grpc@v1.79.3
1.82.2
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/grpc@v1.51.0
1.82.2
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
google.golang.org/grpc@v1.67.1
1.82.2

Open the chart page →

68,765
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/grpc@v1.33.1
1.82.2
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/grpc@v1.53.0
1.82.2

Open the chart page →

5,055
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/grpc@v1.20.1
1.82.2

Open the chart page →

11,981
kube-prometheus-stackdevtron19.3.02 of 6See more

kube-prometheus-stack devtron 19.3.0

2 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/grpc@v1.40.0
1.82.2
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/grpc@v1.38.0
1.82.2

Open the chart page →

8,659
migrantdevtron0.0.31 of 1See more

migrant devtron 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
migrate/migrate:latest76cc2074cb66
google.golang.org/grpc@v1.82.0
1.82.2

Open the chart page →

112
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/grpc@v1.43.0
1.82.2

Open the chart page →

2,442
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/grpc@v1.41.0
1.82.2

Open the chart page →

1,514
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
google.golang.org/grpc@v1.64.0
1.82.2

Open the chart page →

9,703
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/grpc@v1.15.0
1.82.2
quay.io/dexidp/dex:v2.25.07bcf286807b8
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

10,484

Container images carrying it

2,815 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
owncloud/ocis:1.7.0d2efcae92c84
google.golang.org/grpc@v1.38.0
1.82.2
1
owncloud/server:10.15.051d9b74fc2a8
google.golang.org/grpc@v1.64.0
1.82.2
1
owncloud/server:10.16.274c53d341076
google.golang.org/grpc@v1.80.0
1.82.2
1
owncloud/server:10.16.3b3f9efdcd7f7
google.golang.org/grpc@v1.81.1
1.82.2
1
percona/mongodb_exporter:0.53.00214e482b2cd
google.golang.org/grpc@v1.82.1
1.82.2
1
percona/percona-postgresql-operator:2.8.06cce2698d3f5
google.golang.org/grpc@v1.76.0
1.82.2
1
percona/percona-server-mongodb-operator:1.23.0feaff989e253
google.golang.org/grpc@v1.82.1
1.82.2
1
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
google.golang.org/grpc@v1.81.1
1.82.2
1
percona/pmm-server:3.9.1003f9c25f842
google.golang.org/grpc@v1.83.0
1.83.2
1
persesdev/perses:v0.54.0a0e34ddaf9d7
google.golang.org/grpc@v1.82.1
1.82.2
1
pgsharding/spqr-router:nightly-2.8.3-1839-f66048d84734940216d3
google.golang.org/grpc@v1.77.0
1.82.2
1
phntom/chartmuseum:v0.16.053883b65d9b7
google.golang.org/grpc@v1.55.0
1.82.2
1
phntom/chartmuseum:v0.15.29242b4df9e65
google.golang.org/grpc@v1.47.0
1.82.2
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
google.golang.org/grpc@v1.56.1
1.82.2
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
google.golang.org/grpc@v1.27.0
1.82.2
1
pinclr/v2ray-proxy:latestf37f250b7091
google.golang.org/grpc@v1.53.0
1.82.2
1
pipekit13/agent:v7.6.0c3f01b5ac3b2
google.golang.org/grpc@v1.82.1
1.82.2
1
platzio/backend:v0.6.5d5e5972f344b
google.golang.org/grpc@v1.68.1
1.82.2
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
google.golang.org/grpc@v1.24.0
1.82.2
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
google.golang.org/grpc@v1.53.0
1.82.2
1
pomerium/pomerium:v0.22.19c69b10a2126
google.golang.org/grpc@v1.54.0
1.82.2
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
google.golang.org/grpc@v1.49.0
1.82.2
1
portainer/portainer-ce:2.45.0511f3f06c96f
google.golang.org/grpc@v1.82.1
1.82.2
1
posit/package-manager:2026.09.0-ubuntu-24.04527493ef621b
google.golang.org/grpc@v1.82.1
1.82.2
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
google.golang.org/grpc@v1.24.0
1.82.2
1
pritunl/pritunl-zero:1.0.3648.460f2943e0d41b
google.golang.org/grpc@v1.60.1
1.82.2
1
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
google.golang.org/grpc@v1.32.0
1.82.2
1
projectsveltos/access-manager:v1.15.01b396a28296e
google.golang.org/grpc@v1.83.1
1.83.2
1
projectsveltos/classifier:v1.15.0fe379e5bcb87
google.golang.org/grpc@v1.83.1
1.83.2
1
projectsveltos/shard-controller:v1.15.0872e772ff1a1
google.golang.org/grpc@v1.83.1
1.83.2
1
projectsveltos/sveltoscluster-manager:v1.15.0b032d483935e
google.golang.org/grpc@v1.83.1
1.83.2
1
prom/blackbox-exporter:v0.22.0608acee5704a
google.golang.org/grpc@v1.48.0
1.82.2
1
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
google.golang.org/grpc@v1.63.2
1.82.2
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
google.golang.org/grpc@v1.51.0
1.82.2
1
prometheuscommunity/stackdriver-exporter:v0.19.0c0a0cbf76570
google.golang.org/grpc@v1.81.1
1.82.2
1
prom/prometheus:v2.51.24f6c47e39a90
google.golang.org/grpc@v1.62.1
1.82.2
1
prom/prometheus:v2.18.15880ec936055
google.golang.org/grpc@v1.29.0
1.82.2
1
prom/prometheus:v3.12.069f524141883
google.golang.org/grpc@v1.81.1
1.82.2
1
prom/prometheus:v2.48.0b440bc0e8aa5
google.golang.org/grpc@v1.58.3
1.82.2
1
prom/prometheus:v2.19.2cd134bd4fca0
google.golang.org/grpc@v1.29.1
1.82.2
1
prom/prometheus:v3.8.0d936808bdea5
google.golang.org/grpc@v1.76.0
1.82.2
1
prom/prometheus:v2.16.0e4ca62c0d62f
google.golang.org/grpc@v1.22.1
1.82.2
1
prom/prometheus:v2.22.2f7ffebdd428b
google.golang.org/grpc@v1.32.0
1.82.2
1
prom/promlens:v0.4.04a377d1a0eaa
google.golang.org/grpc@v1.82.0
1.82.2
1
prowlercloud/prowler-api:5.31.14f252d579be2
google.golang.org/grpc@v1.80.0
1.82.2
1
pulumi/pulumi-kubernetes-operator:v2.9.16fca5e82daf8
google.golang.org/grpc@v1.83.1
1.83.2
1
pulumi/pulumi-kubernetes-operator:v2.5.17dace4491358
google.golang.org/grpc@v1.72.1
1.82.2
1
qonstrukt/php:8.4-v8-apache089af7925aa1
google.golang.org/grpc@v1.28.0
1.82.2
1
qualys/qscanner:5.1.0-59ff255352422
google.golang.org/grpc@v1.82.1
1.82.2
1
qumine/minecraft-server:v0.1.15c0b650d51132
google.golang.org/grpc@v1.51.0
1.82.2
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.