StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,364
of 17,813 indexed, latest versions
Container images
2,828
deployed by those charts
Fix available
1 of 1
affected package

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,364 of 17,813 indexed charts deploy, on 2,828 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,828
OSV records
GHSA-2v4p-qf9q-27wj
Also known as
GO-2026-6443
Trending
Rank 40 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,364 by stars
ChartLatestAffected imagesRadar Score
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,513
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,624
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.82.2

Open the chart page →

1,061
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

13,907
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
google.golang.org/grpc@v1.72.2
1.82.2

Open the chart page →

402
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.82.2

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

4,926
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.82.2

Open the chart page →

9,738
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.82.2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.82.2

Open the chart page →

9,526
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.82.2

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.82.2
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.82.2
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.82.2
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.82.2

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.82.2
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.82.2
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

5,077

Container images carrying it

2,828 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/containers/nri-plugins/nri-memory-qos:v0.14.0c7c5c24ed894
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/containers/nri-plugins/nri-memtierd:v0.14.09138314e12ba
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/containers/nri-plugins/nri-resctrl-mon:v0.14.0a9c9775fab70
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/containers/nri-plugins/nri-resource-policy-balloons:v0.14.0a8c8297c7274
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/containers/nri-plugins/nri-resource-policy-template:v0.14.00edfc075277b
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/containers/nri-plugins/nri-resource-policy-topology-aware:v0.14.0e2443833726a
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/containers/nri-plugins/nri-sgx-epc:v0.14.0b4c4d0d83c14
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
google.golang.org/grpc@v1.71.0
1.82.2
1
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
google.golang.org/grpc@v1.75.0
1.82.2
1
ghcr.io/crashappsec/chalk-operator:v0.1.128eee62e9bfa
google.golang.org/grpc@v1.68.1
1.82.2
1
ghcr.io/crashappsec/chalkular-controller:v0.0.8d31986456626
google.golang.org/grpc@v1.83.0
1.83.2
1
ghcr.io/crashappsec/ocular-controller:v0.4.122060cf61e0e
google.golang.org/grpc@v1.83.0
1.83.2
1
ghcr.io/crazygit/cert-manager-alidns-webhook:0.1.4976be6506eb6
google.golang.org/grpc@v1.75.1
1.82.2
1
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
google.golang.org/grpc@v1.72.2
1.82.2
1
ghcr.io/crazy-max/diun:4.19.0c94e32b888e4
google.golang.org/grpc@v1.38.0
1.82.2
1
ghcr.io/cronschedules/cronjob-scale-down-operator:0.4.41c4e803d7169
google.golang.org/grpc@v1.80.0
1.82.2
1
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
google.golang.org/grpc@v1.29.1
1.82.2
1
ghcr.io/cybozu-go/moco:0.37.032e7cab1bdd8
google.golang.org/grpc@v1.80.0
1.82.2
1
ghcr.io/d0ugal/internet-perf-exporter:v0.2.91f5c9a96fe52a
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/danieldonoghue/vault-sync-operator:v0.0.1-beta.38d7ec69a193c
google.golang.org/grpc@v1.80.0
1.82.2
1
ghcr.io/dapr/injector:1.17.0-rc.37a2fd888ed5f
google.golang.org/grpc@v1.73.0
1.82.2
1
ghcr.io/dapr/operator:1.17.0-rc.3d5cc61cbe735
google.golang.org/grpc@v1.73.0
1.82.2
1
ghcr.io/dapr/placement:1.17.0-rc.3a237b43cd5c6
google.golang.org/grpc@v1.73.0
1.82.2
1
ghcr.io/dapr/scheduler:1.17.0-rc.36c62e01e736b
google.golang.org/grpc@v1.73.0
1.82.2
1
ghcr.io/dapr/sentry:1.17.0-rc.3bf79b03591e0
google.golang.org/grpc@v1.73.0
1.82.2
1
ghcr.io/dc-tec/openbao-operator:0.5.04f1d8e79e9d3
google.golang.org/grpc@v1.83.0
1.83.2
1
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/devangradadiya/k8s-s3-bucket-operator:0.2.258288de9f9fa
google.golang.org/grpc@v1.72.2
1.82.2
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/dexidp/dex:v2.43.10881d3c9359b
google.golang.org/grpc@v1.71.0
1.82.2
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
google.golang.org/grpc@v1.49.0
1.82.2
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
google.golang.org/grpc@v1.72.1
1.82.2
1
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
google.golang.org/grpc@v1.68.1
1.82.2
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
google.golang.org/grpc@v1.56.1
1.82.2
1
ghcr.io/digitalis-io/vals-operator:v0.8.17c776499b8c9
google.golang.org/grpc@v1.78.0
1.82.2
1
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
google.golang.org/grpc@v1.68.0
1.82.2
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
google.golang.org/grpc@v1.43.0
1.82.2
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
google.golang.org/grpc@v1.46.0
1.82.2
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
google.golang.org/grpc@v1.45.0
1.82.2
1
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
google.golang.org/grpc@v1.82.1
1.82.2
1
ghcr.io/dsp0x4/cloudfront-tenant-operator:0.3.0eb40174cd20d
google.golang.org/grpc@v1.79.3
1.82.2
1
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
google.golang.org/grpc@v1.83.0
1.83.2
1
ghcr.io/edgelesssys/continuum/continuum-proxy24c76f294a80
google.golang.org/grpc@v1.69.0
1.82.2
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
google.golang.org/grpc@v1.36.0
1.82.2
1
ghcr.io/element-hq/lk-jwt-service:0.6.0822f0c03a3bd
google.golang.org/grpc@v1.81.1
1.82.2
1
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
google.golang.org/grpc@v1.67.3
1.82.2
1
ghcr.io/emqx/emqx-operator:2.3.23333ed546165
google.golang.org/grpc@v1.65.0
1.82.2
1
ghcr.io/ente/server:0472c929b6070e61fecaf2013d47efce2dcda462f646b68a1b8d
google.golang.org/grpc@v1.82.1
1.82.2
1
ghcr.io/eraser-dev/eraser-manager:v1.4.2cda6025d1152
google.golang.org/grpc@v1.82.1
1.82.2
1
ghcr.io/erpc/erpc:0.1.18bfed3d49a08
google.golang.org/grpc@v1.81.1
1.82.2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.