StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,364
of 17,813 indexed, latest versions
Container images
2,828
deployed by those charts
Fix available
1 of 1
affected package

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,364 of 17,813 indexed charts deploy, on 2,828 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,828
OSV records
GHSA-2v4p-qf9q-27wj
Also known as
GO-2026-6443
Trending
Rank 40 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,364 by stars
ChartLatestAffected imagesRadar Score
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,513
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

2,624
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.82.2

Open the chart page →

1,061
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

13,907
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
google.golang.org/grpc@v1.72.2
1.82.2

Open the chart page →

402
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
google.golang.org/grpc@v1.73.0
1.82.2

Open the chart page →

1,197
fleet-managementxxl-job-adminVerified publisher1.0.01 of 1See more

fleet-management xxl-job-admin 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/alloy-remote-config/fleet-management:master4371b566d238
google.golang.org/grpc@v1.79.3
1.82.2

Open the chart page →

238
kadalu-operatorxxl-job-adminVerified publisher1.2.41 of 4See more

kadalu-operator xxl-job-admin 1.2.4

1 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
google.golang.org/grpc@v1.27.0
1.82.2

Open the chart page →

4,926
nightingalexxl-job-adminVerified publisher0.2.112 of 6See more

nightingale xxl-job-admin 0.2.11

2 of the 6 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
google.golang.org/grpc@v1.65.0
1.82.2

Open the chart page →

9,738
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.82.2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.82.2

Open the chart page →

9,526
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.82.2

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.82.2
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.82.2
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.82.2
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.82.2

Open the chart page →

8,002
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.82.2
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

936
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.82.2
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

5,077

Container images carrying it

2,828 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/jetstack/cert-manager-webhook:v1.18.29431f0d8b510
google.golang.org/grpc@v1.69.2
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
google.golang.org/grpc@v1.43.0
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.21.1d8b3961b51c8
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
google.golang.org/grpc@v1.54.0
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.14.5ef419261a209
google.golang.org/grpc@v1.60.1
1.82.2
1
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
google.golang.org/grpc@v1.43.0
1.82.2
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
google.golang.org/grpc@v1.26.0
1.82.2
1
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
google.golang.org/grpc@v1.63.2
1.82.2
1
quay.io/kiali/kiali:v2.23.07652b1285f50
google.golang.org/grpc@v1.78.0
1.82.2
1
quay.io/kiali/kiali:v2.32.0b171d679be27
google.golang.org/grpc@v1.81.1
1.82.2
1
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
google.golang.org/grpc@v1.66.0
1.82.2
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
google.golang.org/grpc@v1.58.3
1.82.2
1
quay.io/kuadrant/kuadrant-operator:v1.5.318ad777aeb7a
google.golang.org/grpc@v1.83.1
1.83.2
1
quay.io/kube-ops/loki:2.2.14fbd63194674
google.golang.org/grpc@v1.29.1
1.82.2
1
quay.io/kube-ops/promtail:2.2.134de6387233b
google.golang.org/grpc@v1.29.1
1.82.2
1
quay.io/kuberay/security-proxy:nightly4525b5acd23c
google.golang.org/grpc@v1.79.3
1.82.2
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
google.golang.org/grpc@v1.57.1
1.82.2
1
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
google.golang.org/grpc@v1.51.0
1.82.2
1
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
google.golang.org/grpc@v1.27.1
1.82.2
1
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
google.golang.org/grpc@v1.38.0
1.82.2
1
quay.io/kubescape/kubescape:v4.0.1358651dce3376
google.golang.org/grpc@v1.83.1
1.83.2
1
quay.io/kubescape/kubevuln:v0.3.4309bed2f723ea0
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/kubescape/operator:v0.2.16901b2694425e9
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/kubescape/storage:v0.0.33101f2b053ace1
google.golang.org/grpc@v1.82.1
1.82.2
1
quay.io/kubev2v/forklift-operator:release-2.1268657c36c086
google.golang.org/grpc@v1.79.3
1.82.2
1
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
google.golang.org/grpc@v1.68.1
1.82.2
1
quay.io/maxiv/mortalgpu:1.3.7e1c5c194bbf0
google.golang.org/grpc@v1.81.1
1.82.2
1
quay.io/minio/csi-node-driver-registrarc805fdc16676
google.golang.org/grpc@v1.54.0
1.82.2
1
quay.io/minio/csi-provisioner7b5c070ec70d
google.golang.org/grpc@v1.54.0
1.82.2
1
quay.io/minio/csi-resizer819f68a4daf7
google.golang.org/grpc@v1.51.0
1.82.2
1
quay.io/minio/directpv:v4.0.84560083eb77d
google.golang.org/grpc@v1.53.0
1.82.2
1
quay.io/minio/livenessprobef3bc9a84f149
google.golang.org/grpc@v1.51.0
1.82.2
1
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
google.golang.org/grpc@v1.60.1
1.82.2
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
google.golang.org/grpc@v1.50.1
1.82.2
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
google.golang.org/grpc@v1.44.0
1.82.2
1
quay.io/minio/mc:RELEASE.2024-04-29T09-56-05Zc574fac67f60
google.golang.org/grpc@v1.63.2
1.82.2
1
quay.io/minio/minio:RELEASE.2023-12-20T01-00-02Z5702ea361420
google.golang.org/grpc@v1.60.1
1.82.2
1
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
google.golang.org/grpc@v1.60.1
1.82.2
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
google.golang.org/grpc@v1.49.0
1.82.2
1
quay.io/minio/minio:RELEASE.2024-06-04T19-20-08Zc6b68f158628
google.golang.org/grpc@v1.63.2
1.82.2
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
google.golang.org/grpc@v1.50.1
1.82.2
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
google.golang.org/grpc@v1.53.0
1.82.2
1
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
google.golang.org/grpc@v1.60.1
1.82.2
1
quay.io/mongodb/mongodb-kubernetes:1.12.014d7c95972c5
google.golang.org/grpc@v1.83.1
1.83.2
1
quay.io/netobserv/network-observability-operator:1.12.0-communityb05d21a015b0
google.golang.org/grpc@v1.81.1
1.82.2
1
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
google.golang.org/grpc@v1.80.0
1.82.2
1
quay.io/oauth2-proxy/oauth2-proxy:v7.15.310a1165743a1
google.golang.org/grpc@v1.81.1
1.82.2
1
quay.io/oauth2-proxy/oauth2-proxy:v7.13.056e3daedf765
google.golang.org/grpc@v1.73.0
1.82.2
1
quay.io/oauth2-proxy/oauth2-proxy:v7.14.368336da945bd
google.golang.org/grpc@v1.78.0
1.82.2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.