StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,299
of 17,797 indexed, latest versions
Container images
2,795
deployed by those charts
Fix available
1 of 1
affected package

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,299 of 17,797 indexed charts deploy, on 2,795 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,795
OSV records
GHSA-2v4p-qf9q-27wj
Also known as
GO-2026-6443
Trending
Rank 7 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,299 by stars
ChartLatestAffected imagesRadar Score
kong-meshkong-meshVerified publisher2.14.42 of 3See more

kong-mesh kong-mesh 2.14.4

2 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kong/kuma-cp:2.14.47e4f53630a28
google.golang.org/grpc@v1.83.1
1.83.2
kong/kumactl:2.14.463d11b2d3f60
google.golang.org/grpc@v1.83.1
1.83.2

Open the chart page →

560
kubeflowkubeflow1.6.218 of 45See more

kubeflow kubeflow 1.6.2

18 of the 45 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
google.golang.org/grpc@v1.36.0
1.82.2
istio/proxyv2:1.14.1df69c1a7af7c
google.golang.org/grpc@v1.45.0
1.82.2
kserve/kserve-controller:v0.8.0f0692a9ea09f
google.golang.org/grpc@v1.42.0
1.82.2
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
google.golang.org/grpc@v1.42.0
1.82.2
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
google.golang.org/grpc@v1.42.0
1.82.2
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
google.golang.org/grpc@v1.42.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
google.golang.org/grpc@v1.44.0
1.82.2
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
google.golang.org/grpc@v1.44.0
1.82.2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

97,283
testkubekubeshop2.13.22 of 5See more

testkube kubeshop 2.13.2

2 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kubeshop/testkube-api-server:2.13.244166c28422f
google.golang.org/grpc@v1.83.1
1.83.2
kubeshop/testkube-minio:2025.10d8e1af6aca99
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

5,178
openelbkubesphere-stable0.5.01 of 2See more

openelb kubesphere-stable 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

4,336
sbomscannerkubewardenVerified publisher0.12.13 of 5See more

sbomscanner kubewarden 0.12.1

3 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/kubewarden/sbomscanner/controller:v0.12.1153ccb651e49
google.golang.org/grpc@v1.83.1
1.83.2
ghcr.io/kubewarden/sbomscanner/storage:v0.12.1811ed0383187
google.golang.org/grpc@v1.83.1
1.83.2
ghcr.io/kubewarden/sbomscanner/worker:v0.12.1b4274b7cc473
google.golang.org/grpc@v1.83.1
1.83.2

Open the chart page →

1,012
venti-stackkuossOfficialVerified publisher0.5.03 of 9See more

venti-stack kuoss 0.5.0

3 of the 9 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.34.0690c7b525f43
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:v3.13.2508729e0e2d1
google.golang.org/grpc@v1.82.1
1.82.2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.19.185108987d044
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

3,830
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

4,109
vclustermainVerified publisher0.17.06 of 10See more

vcluster main 0.17.0

6 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
google.golang.org/grpc@v1.51.0
1.82.2
registry.k8s.io/etcd:3.6.4-0e36c08168342
google.golang.org/grpc@v1.71.1
1.82.2
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
google.golang.org/grpc@v1.40.0
1.82.2
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
google.golang.org/grpc@v1.47.0
1.82.2
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
google.golang.org/grpc@v1.47.0
1.82.2
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
google.golang.org/grpc@v1.47.0
1.82.2

Open the chart page →

11,598
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
headscale/headscale:0.25.1a7a8ae9616bb
google.golang.org/grpc@v1.69.0
1.82.2

Open the chart page →

8,024
node-local-dnsnode-local-dns2.4.01 of 1See more

node-local-dns node-local-dns 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
google.golang.org/grpc@v1.56.3
1.82.2

Open the chart page →

2,626
nri-memtierdnri-pluginsOfficialVerified publisher0.14.01 of 1See more

nri-memtierd nri-plugins 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/containers/nri-plugins/nri-memtierd:v0.14.09138314e12ba
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

276
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
google.golang.org/grpc@v1.56.1
1.82.2

Open the chart page →

8,788
capsuleprojectcapsuleOfficialVerified publisher0.14.61 of 2See more

capsule projectcapsule 0.14.6

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

1,238
proxmox-cloud-controller-managerproxmox-ccm0.2.301 of 1See more

proxmox-cloud-controller-manager proxmox-ccm 0.2.30

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/proxmox-cloud-controller-manager:v0.15.0fbc553921145
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

115
rke2-multusrke2-charts3.7.1-build20210416011 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
google.golang.org/grpc@v1.23.0
1.82.2

Open the chart page →

4,526
fulciosigstoreVerified publisher2.11.14 of 6See more

fulcio sigstore 2.11.1

4 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/sigstore/fulcio:v1.8.8ef72cf56c64b
google.golang.org/grpc@v1.81.1
1.82.2
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
google.golang.org/grpc@v1.76.0
1.82.2
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
google.golang.org/grpc@v1.76.0
1.82.2
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
google.golang.org/grpc@v1.76.0
1.82.2

Open the chart page →

3,518
policy-controllersigstoreVerified publisher0.10.81 of 2See more

policy-controller sigstore 0.10.8

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/sigstore/policy-controller/policy-controllerdigest-pinned0bcd60beb93f
google.golang.org/grpc@v1.71.1
1.82.2

Open the chart page →

918
pubsubplus-hasolaceVerified publisher3.10.01 of 1See more

pubsubplus-ha solace 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
solace/solace-pubsub-standard:latest8e8ad105595e
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

285
sops-secrets-operatorsops-secrets-operatorVerified publisher0.28.11 of 1See more

sops-secrets-operator sops-secrets-operator 0.28.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

842
steampipe-powerpipe-kubernetessteampipe-powerpipe-kubernetesVerified publisher0.13.12 of 2See more

steampipe-powerpipe-kubernetes steampipe-powerpipe-kubernetes 0.13.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
google.golang.org/grpc@v1.79.3
1.82.2
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

5,538
topolvmtopolvmVerified publisher17.2.01 of 1See more

topolvm topolvm 17.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
google.golang.org/grpc@v1.78.0
1.82.2

Open the chart page →

2,393
uffizzi-appuffizzi-app1.3.03 of 14See more

uffizzi-app uffizzi-app 1.3.0

3 of the 14 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
google.golang.org/grpc@v1.58.3
1.82.2
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
google.golang.org/grpc@v1.58.3
1.82.2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
google.golang.org/grpc@v1.58.3
1.82.2

Open the chart page →

19,431
valdvald1.8.04 of 5See more

vald vald 1.8.0

4 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
vdaas/vald-agent-ngt:v1.8.032e3695fe585
google.golang.org/grpc@v1.83.0
1.83.2
vdaas/vald-discoverer-k8s:v1.8.0f6495f38ae92
google.golang.org/grpc@v1.83.0
1.83.2
vdaas/vald-lb-gateway:v1.8.061009e319a9a
google.golang.org/grpc@v1.83.0
1.83.2
vdaas/vald-manager-index:v1.8.0ab881d2262d8
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

216
vault-operatorvault-operatorVerified publisher1.24.01 of 1See more

vault-operator vault-operator 1.24.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-operator:v1.24.06f622c5fb8a9
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

542
vault-secrets-webhookvault-secrets-webhookVerified publisher1.23.11 of 1See more

vault-secrets-webhook vault-secrets-webhook 1.23.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/bank-vaults/vault-secrets-webhook:v1.23.198baf045a1c9
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

526
athens-proxyvolker-raschekVerified publisher2.0.31 of 1See more

athens-proxy volker-raschek 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
gomods/athens:v0.17.10f61d1e62359
google.golang.org/grpc@v1.80.0
1.82.2

Open the chart page →

2,042
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
google.golang.org/grpc@v1.26.0
1.82.2

Open the chart page →

13,587
yunikornyunikornVerified publisher1.9.02 of 3See more

yunikorn yunikorn 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
apache/yunikorn:scheduler-1.9.096832082e9cf
google.golang.org/grpc@v1.79.3
1.82.2
apache/yunikorn:admission-1.9.0fe8f5ec91f6c
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

412
aperture-controlleraperture2.34.02 of 5See more

aperture-controller aperture 2.34.0

2 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
fluxninja/aperture-operator:2.34.0356d7aa86632
google.golang.org/grpc@v1.60.1
1.82.2
quay.io/prometheus/prometheus:v2.33.591100b06e86d
google.golang.org/grpc@v1.43.0
1.82.2

Open the chart page →

4,679
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
google.golang.org/grpc@v1.38.0
1.82.2

Open the chart page →

3,308
athens-proxyathens-chartsOfficialVerified publisher0.17.11 of 1See more

athens-proxy athens-charts 0.17.1

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
gomods/athens:v0.18.197cc113b34b0
google.golang.org/grpc@v1.81.1
1.82.2

Open the chart page →

1,299
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
google.golang.org/grpc@v1.38.0
1.82.2

Open the chart page →

9,061
prometheusaveshaVerified publisher19.3.01 of 4See more

prometheus avesha 19.3.0

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
google.golang.org/grpc@v1.51.0
1.82.2

Open the chart page →

5,491
snapschedulerbackube-helm-chartsVerified publisher3.5.01 of 2See more

snapscheduler backube-helm-charts 3.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
google.golang.org/grpc@v1.65.0
1.82.2

Open the chart page →

1,232
boundaryboundaryVerified publisher0.1.01 of 1See more

boundary boundary 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/boundary:0.21.037bf86488b74
google.golang.org/grpc@v1.76.0
1.82.2

Open the chart page →

1,445
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
google.golang.org/grpc@v1.59.0
1.82.2

Open the chart page →

1,891
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
google.golang.org/grpc@v1.51.0
1.82.2

Open the chart page →

1,705
cert-managerchoerodon1.8.23 of 4See more

cert-manager choerodon 1.8.2

3 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
google.golang.org/grpc@v1.43.0
1.82.2
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
google.golang.org/grpc@v1.43.0
1.82.2
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
google.golang.org/grpc@v1.43.0
1.82.2

Open the chart page →

7,797
cloudprobercloudproberOfficialVerified publisher1.14.251 of 1See more

cloudprober cloudprober 1.14.25

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cloudprober/cloudprober:v0.14.540c6d960ae4f
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

219
dumpscriptcloudscriptVerified publisher1.8.31 of 1See more

dumpscript cloudscript 1.8.3

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
google.golang.org/grpc@v1.76.0
1.82.2

Open the chart page →

2,128
cluster-manager-servercluster-manager-server1.8.01 of 1See more

cluster-manager-server cluster-manager-server 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
google.golang.org/grpc@v1.68.1
1.82.2

Open the chart page →

753
coder-observabilitycoder-observabilityVerified publisher0.7.38 of 21See more

coder-observability coder-observability 0.7.3

8 of the 21 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
burningalchemist/sql_exporter:latest2586aa37f140
google.golang.org/grpc@v1.83.1
1.83.2
grafana/agent:v0.40.3f6cbec9409be
google.golang.org/grpc@v1.61.0
1.82.2
grafana/grafana:10.4.19a9043254ba16
google.golang.org/grpc@v1.71.0
1.82.2
grafana/loki:3.1.0d947e68a84d9
google.golang.org/grpc@v1.62.1
1.82.2
grafana/loki-canary:3.1.039baf6d67f85
google.golang.org/grpc@v1.62.1
1.82.2
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
google.golang.org/grpc@v1.44.0
1.82.2
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
google.golang.org/grpc@v1.49.0
1.82.2
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
google.golang.org/grpc@v1.64.0
1.82.2

Open the chart page →

24,755
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
google.golang.org/grpc@v1.59.0
1.82.2

Open the chart page →

17,632
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
google.golang.org/grpc@v1.39.0
1.82.2

Open the chart page →

3,088
cosmocosmo-platformOfficialVerified publisher0.20.02 of 10See more

cosmo cosmo-platform 0.20.0

2 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
google.golang.org/grpc@v1.71.0
1.82.2
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
google.golang.org/grpc@v1.64.0
1.82.2

Open the chart page →

29,096
ocularcrashoverride-helm-chartsVerified publisher0.5.21 of 1See more

ocular crashoverride-helm-charts 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/crashappsec/ocular-controller:v0.4.122060cf61e0e
google.golang.org/grpc@v1.83.0
1.83.2

Open the chart page →

37
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
google.golang.org/grpc@v1.61.0
1.82.2

Open the chart page →

1,310
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
google.golang.org/grpc@v1.59.0
1.82.2

Open the chart page →

3,461
distrdistrOfficialVerified publisher4.0.32See more

distr distr 4.0.3

2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/loki:3.7.7d70e4659623f
google.golang.org/grpc@v1.82.1
1.82.2
rclone/rclone:1.75.145401ad7410d
google.golang.org/grpc@v1.84.0-dev.0.20260723093437-b6eac429d7b6
1.85.0-dev.0.20260825072537-93e31b48545e

Open the chart page →

bscdysnixVerified publisher0.6.591 of 4See more

bsc dysnix 0.6.59

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/bnb-chain/bsc:1.6.2fd0e3ec7d960
google.golang.org/grpc@v1.69.4
1.82.2

Open the chart page →

2,016

Container images carrying it

2,795 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/jetstack/cert-manager-controller:v1.21.1416a2d76870d
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
google.golang.org/grpc@v1.54.0
1.82.2
1
quay.io/jetstack/cert-manager-controller:v1.18.281316365dc0b
google.golang.org/grpc@v1.69.2
1.82.2
1
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
google.golang.org/grpc@v1.60.1
1.82.2
1
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
google.golang.org/grpc@v1.43.0
1.82.2
1
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
google.golang.org/grpc@v1.66.2
1.82.2
1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
google.golang.org/grpc@v1.43.0
1.82.2
1
quay.io/jetstack/cert-manager-controller:v1.21.0e370f7800a53
google.golang.org/grpc@v1.81.1
1.82.2
1
quay.io/jetstack/cert-manager-csi-driver:v0.16.09d13db6dc80e
google.golang.org/grpc@v1.83.0
1.83.2
1
quay.io/jetstack/cert-manager-csi-driver-spiffe:v0.15.01755a3802efd
google.golang.org/grpc@v1.83.0
1.83.2
1
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
google.golang.org/grpc@v1.58.3
1.82.2
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
google.golang.org/grpc@v1.43.0
1.82.2
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
google.golang.org/grpc@v1.43.0
1.82.2
1
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
google.golang.org/grpc@v1.54.0
1.82.2
1
quay.io/jetstack/cert-manager-google-cas-issuer:v0.12.08bd9cdb714a6
google.golang.org/grpc@v1.80.0
1.82.2
1
quay.io/jetstack/cert-manager-istio-csr:v0.17.0c38a38fcd2dd
google.golang.org/grpc@v1.83.0
1.83.2
1
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
google.golang.org/grpc@v1.47.0
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
google.golang.org/grpc@v1.66.2
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.18.29431f0d8b510
google.golang.org/grpc@v1.69.2
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
google.golang.org/grpc@v1.43.0
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.21.0c33cca307541
google.golang.org/grpc@v1.81.1
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.21.1d8b3961b51c8
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
google.golang.org/grpc@v1.54.0
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.14.5ef419261a209
google.golang.org/grpc@v1.60.1
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
google.golang.org/grpc@v1.43.0
1.82.2
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
google.golang.org/grpc@v1.26.0
1.82.2
1
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
google.golang.org/grpc@v1.63.2
1.82.2
1
quay.io/kiali/kiali:v2.23.07652b1285f50
google.golang.org/grpc@v1.78.0
1.82.2
1
quay.io/kiali/kiali:v2.32.0b171d679be27
google.golang.org/grpc@v1.81.1
1.82.2
1
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
google.golang.org/grpc@v1.66.0
1.82.2
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
google.golang.org/grpc@v1.58.3
1.82.2
1
quay.io/kuadrant/kuadrant-operator:v1.5.318ad777aeb7a
google.golang.org/grpc@v1.83.1
1.83.2
1
quay.io/kube-ops/loki:2.2.14fbd63194674
google.golang.org/grpc@v1.29.1
1.82.2
1
quay.io/kube-ops/promtail:2.2.134de6387233b
google.golang.org/grpc@v1.29.1
1.82.2
1
quay.io/kuberay/apiserver:v1.7.05bb3ad7621c8
google.golang.org/grpc@v1.79.3
1.82.2
1
quay.io/kuberay/security-proxy:nightly4525b5acd23c
google.golang.org/grpc@v1.79.3
1.82.2
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
google.golang.org/grpc@v1.57.1
1.82.2
1
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
google.golang.org/grpc@v1.51.0
1.82.2
1
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
google.golang.org/grpc@v1.27.1
1.82.2
1
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
google.golang.org/grpc@v1.38.0
1.82.2
1
quay.io/kubescape/kubescape:v4.0.1358651dce3376
google.golang.org/grpc@v1.83.1
1.83.2
1
quay.io/kubescape/kubevuln:v0.3.4309bed2f723ea0
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/kubescape/operator:v0.2.16901b2694425e9
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/kubescape/storage:v0.0.33101f2b053ace1
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/kubev2v/forklift-operator:release-2.1268657c36c086
google.golang.org/grpc@v1.79.3
1.82.2
1
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
google.golang.org/grpc@v1.68.1
1.82.2
1
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
google.golang.org/grpc@v1.81.1
1.82.2
1
quay.io/minio/csi-node-driver-registrarc805fdc16676
google.golang.org/grpc@v1.54.0
1.82.2
1
quay.io/minio/csi-provisioner7b5c070ec70d
google.golang.org/grpc@v1.54.0
1.82.2
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.