StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,364
of 17,813 indexed, latest versions
Container images
2,828
deployed by those charts
Fix available
1 of 1
affected package

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,364 of 17,813 indexed charts deploy, on 2,828 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,828
OSV records
GHSA-2v4p-qf9q-27wj
Also known as
GO-2026-6443
Trending
Rank 40 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,364 by stars
ChartLatestAffected imagesRadar Score
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,513
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,624
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.82.2

Open the chart page →

1,061
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

13,907
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
google.golang.org/grpc@v1.72.2
1.82.2

Open the chart page →

402
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.82.2

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

4,926
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.82.2

Open the chart page →

9,738
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.82.2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.82.2

Open the chart page →

9,526
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.82.2

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.82.2
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.82.2
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.82.2
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.82.2

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.82.2
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.82.2
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

5,077

Container images carrying it

2,828 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/bbdsoftware/litellm-operator:1.1.2167a51113d90
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
google.golang.org/grpc@v1.57.0
1.82.2
1
ghcr.io/bionicstork/bionicstork/relay:latest13290b9a64af
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
google.golang.org/grpc@v1.81.0
1.82.2
1
ghcr.io/bitwarden/sm-operator:2.1.0846624161f32
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/blind-oracle/cortex-tenant:v2.0.09f8896ffc15b
google.golang.org/grpc@v1.71.0
1.82.2
1
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
google.golang.org/grpc@v1.69.4
1.82.2
1
ghcr.io/bodgit/nri-plugin-runtime:v0.0.3130c0b1b6fa3
google.golang.org/grpc@v1.57.1
1.82.2
1
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
google.golang.org/grpc@v1.65.0
1.82.2
1
ghcr.io/borchero/switchboard:0.7.454a193b757da
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
google.golang.org/grpc@v1.73.0
1.82.2
1
ghcr.io/buildbarn/bb-scheduler:20260908T142432Z-77f7642f627ab242890
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/buildbarn/bb-storage:20260908T142448Z-db6204132ebc54b769b
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/buoyantio/controller:preview-26.8.431a2f3922a61
google.golang.org/grpc@v1.83.0
1.83.2
1
ghcr.io/buoyantio/linkerd-dashboard-server:0.11.1dd6a29588242
google.golang.org/grpc@v1.83.0
1.83.2
1
ghcr.io/buoyantio/metrics-api:preview-25.4.32cef2a3f97da
google.golang.org/grpc@v1.71.1
1.82.2
1
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
google.golang.org/grpc@v1.71.0
1.82.2
1
ghcr.io/buoyantio/tap:preview-25.4.3e02a8bd9e2c3
google.golang.org/grpc@v1.71.1
1.82.2
1
ghcr.io/buoyantio/web:preview-25.4.33ee1b62aa111
google.golang.org/grpc@v1.71.1
1.82.2
1
ghcr.io/caas-team/gokubedownscaler:1.3.4cea3dd2f1312
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
google.golang.org/grpc@v1.68.1
1.82.2
1
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
google.golang.org/grpc@v1.68.1
1.82.2
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
google.golang.org/grpc@v1.59.0
1.82.2
1
ghcr.io/caninehq/canine:latesta058034ca006
google.golang.org/grpc@v1.65.0
1.82.2
1
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.82.2
1
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
google.golang.org/grpc@v1.68.0
1.82.2
1
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
google.golang.org/grpc@v1.75.1
1.82.2
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
google.golang.org/grpc@v1.65.0
1.82.2
1
ghcr.io/cerbos/cerbos:0.55.04b9d3b58c4f1
google.golang.org/grpc@v1.83.0
1.83.2
1
ghcr.io/cerbos/cerbos:0.51.08d35a64e4a99
google.golang.org/grpc@v1.78.0
1.82.2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
google.golang.org/grpc@v1.58.3
1.82.2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
google.golang.org/grpc@v1.43.0
1.82.2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
google.golang.org/grpc@v1.73.0
1.82.2
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
google.golang.org/grpc@v1.58.3
1.82.2
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
google.golang.org/grpc@v1.43.0
1.82.2
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.0e7f9e8f1d565
google.golang.org/grpc@v1.73.0
1.82.2
1
ghcr.io/chaos-mesh/chaos-mesh:v2.8.0091b906a0b13
google.golang.org/grpc@v1.73.0
1.82.2
1
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
google.golang.org/grpc@v1.43.0
1.82.2
1
ghcr.io/chaos-mesh/chaos-mesh:v2.7.28bc853c7414c
google.golang.org/grpc@v1.58.3
1.82.2
1
ghcr.io/chaos-mesh/chaos-mesh:v2.8.49e48285bb44c
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/chaos-mesh/chaos-mesh:v2.8.3bdb31f3121a2
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/ckotzbauer/vulnerability-operator:0.28.167008df32715c
google.golang.org/grpc@v1.80.0
1.82.2
1
ghcr.io/clickhouse/clickhouse-operator:v0.0.7d51ca53f0967
google.golang.org/grpc@v1.82.0
1.82.2
1
ghcr.io/clm-cloud-solutions/kubebolt/api:2.1.0546d074f0dfb
google.golang.org/grpc@v1.83.1
1.83.2
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.28.034198e85b6e6
google.golang.org/grpc@v1.77.0
1.82.2
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.30.0a2701eb97cdd
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/cloudprober/cloudprober:v0.14.540c6d960ae4f
google.golang.org/grpc@v1.82.1
1.82.2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.