StackRadar

CVE-2026-84445

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,308
of 17,792 indexed, latest versions
Container images
2,790
deployed by those charts
Fix available
2 of 2
affected packages

gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

Carried by container images the latest versions of 2,308 of 17,792 indexed charts deploy, on 2,790 images.

Affected packageAffected versionsFixed inImages
google.golang.org/grpcgolangv0.0.0-20160317175043-d3ddb4469d5a, v0.0.0-20170216003643-d0c32ee6a441, v1.10.0, v1.14.0+117 more1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e2,789
kubernetes-1.34apk1.34.11-r21.34.11-r81
OSV records
GHSA-2v4p-qf9q-27wjCGA-2675-68qh-x3xm
Also known as
CGA-2rc7-c9wv-rg9j, CGA-2v9r-g7hg-wjpv, CGA-5pg3-vg83-278x, CGA-6jwq-4523-qrxc, CGA-6mqf-6cj9-rr4r, CGA-8vf4-hpwm-ghh8, CGA-96jx-jhxg-fxww, CGA-fg8c-vc3x-88hf, CGA-g3hq-cpjp-v4p5, CGA-hx92-g8xp-6m86, CGA-wgvj-wq84-52gh, GO-2026-6443
Trending
Rank 7 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

2,308 by stars
ChartLatestAffected imagesRadar Score
xboardxboard0.2.01 of 1See more

xboard xboard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
ghcr.io/cedar2025/xboard:latest896e4926e0d7
google.golang.org/grpc@v1.81.0
1.82.2

Open the chart page →

1,049
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

13,783
xonodepoolsxonodepoolsOfficialVerified publisher1.0.71 of 1See more

xonodepools xonodepools 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
xosphere/xonodepools:1.0.71458097b6f85
google.golang.org/grpc@v1.72.2
1.82.2

Open the chart page →

394
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
google.golang.org/grpc@v1.69.2
1.82.2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
google.golang.org/grpc@v1.69.0
1.82.2

Open the chart page →

9,395
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
google.golang.org/grpc@v1.40.0
1.82.2

Open the chart page →

1,965
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
google.golang.org/grpc@v1.40.0
1.82.2
matrixdb/rawfile-csi:v0.2.195b2e38e913d
google.golang.org/grpc@v1.45.0
1.82.2
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
google.golang.org/grpc@v1.36.0
1.82.2
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
google.golang.org/grpc@v1.36.0
1.82.2

Open the chart page →

7,998
prometheus-monitoring-stackyotron-helm-charts1.2.03 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

3 of the 3 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
google.golang.org/grpc@v1.81.1
1.82.2
quay.io/prometheus/alertmanager:latest690c7b525f43
google.golang.org/grpc@v1.82.1
1.82.2
quay.io/prometheus/prometheus:latest5ce7540c3c00
google.golang.org/grpc@v1.82.1
1.82.2

Open the chart page →

899
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-84445.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/grpc@v1.49.0
1.82.2
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/grpc@v1.49.0
1.82.2

Open the chart page →

5,047

Container images carrying it

2,790 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
google.golang.org/grpc@v1.75.1
1.82.2
2
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
google.golang.org/grpc@v1.29.1
1.82.2
2
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
google.golang.org/grpc@v1.29.1
1.82.2
2
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
google.golang.org/grpc@v1.70.0
1.82.2
2
ghcr.io/containerd/nydus-snapshotter:v0.9.056f8617363b4
google.golang.org/grpc@v1.53.0
1.82.2
2
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
google.golang.org/grpc@v1.72.2
1.82.2
2
ghcr.io/dapr/injector:1.18.45ac0db7ca106
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/dapr/operator:1.18.4af58fae3e7c9
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/dapr/placement:1.18.490d2293f42a3
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/dapr/scheduler:1.18.4239eac864320
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/dapr/sentry:1.18.405286fc952e7
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
google.golang.org/grpc@v1.34.0
1.82.2
2
ghcr.io/fluxcd/flux-cli:v2.9.1020edbaee890
google.golang.org/grpc@v1.80.0
1.82.2
2
ghcr.io/fluxcd/helm-controller:v1.6.2e17ab0e5885d
google.golang.org/grpc@v1.80.0
1.82.2
2
ghcr.io/fluxcd/source-controller:v1.9.22b8d06650a1b
google.golang.org/grpc@v1.81.1
1.82.2
2
ghcr.io/glassflow/glassflow-etl-k8s-operator:v3.2.1e70364e88629
google.golang.org/grpc@v1.75.0
1.82.2
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
google.golang.org/grpc@v1.64.0
1.82.2
2
ghcr.io/headlamp-k8s/headlamp:v0.45.0db3f0e0fc58d
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/juanfont/headscale:0.29.3:v0.29.30e7f1c6e4ce6
google.golang.org/grpc@v1.81.1
1.82.2
2
ghcr.io/juniorjpdj/containers/openssl-kubectl:1.36.1-r358afba209ea0
google.golang.org/grpc@v1.79.3
1.82.2
2
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
google.golang.org/grpc@v1.58.3
1.82.2
2
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
google.golang.org/grpc@v1.68.0
1.82.2
2
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
google.golang.org/grpc@v1.68.0
1.82.2
2
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
google.golang.org/grpc@v1.65.0
1.82.2
2
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
google.golang.org/grpc@v1.58.3
1.82.2
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
google.golang.org/grpc@v1.71.0
1.82.2
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
google.golang.org/grpc@v1.71.0
1.82.2
2
ghcr.io/opencost/opencost:1.121.2de2784434527
google.golang.org/grpc@v1.79.3
1.82.2
2
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
google.golang.org/grpc@v1.55.0
1.82.2
2
ghcr.io/projectcapsule/capsule:v0.14.6ac02588e65e8
google.golang.org/grpc@v1.83.0
1.83.2
2
ghcr.io/project-zot/zot:v2.1.216b69512c00dc
google.golang.org/grpc@v1.83.1
1.83.2
2
ghcr.io/quenchworks/images/alertmanager7131b1e72afc
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/quenchworks/images/coolify-realtimef128e512c9c0
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/quenchworks/images/loki97bbf905a6c1
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/quenchworks/images/otel-collector695e7fd14483
google.golang.org/grpc@v1.83.0
1.83.2
2
ghcr.io/quenchworks/images/prometheuse9037c190bc1
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/quenchworks/images/tempo9e889ec33f96
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/rabbitmq/messaging-topology-operator:1.19.124c4649ef3ef
google.golang.org/grpc@v1.80.0
1.82.2
2
ghcr.io/sigstore/fulcio:v1.8.8ef72cf56c64b
google.golang.org/grpc@v1.81.1
1.82.2
2
ghcr.io/sigstore/rekor/rekor-server:v1.5.4100d793d68d0
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
google.golang.org/grpc@v1.51.0
1.82.2
2
ghcr.io/spiffe/oidc-discovery-provider:1.15.3bb95f13c2b4e
google.golang.org/grpc@v1.83.0
1.83.2
2
ghcr.io/spiffe/spiffe-csi-driver:0.2.79dfe4f0caff0
google.golang.org/grpc@v1.71.0
1.82.2
2
ghcr.io/spiffe/spiffe-helper:0.11.01c92e5998ad3
google.golang.org/grpc@v1.76.0
1.82.2
2
ghcr.io/spiffe/spire-controller-manager:0.7.0d7b9e710f542
google.golang.org/grpc@v1.82.1
1.82.2
2
ghcr.io/spiffe/spire-server:1.15.34082f30d3e0d
google.golang.org/grpc@v1.83.0
1.83.2
2
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
google.golang.org/grpc@v1.56.3
1.82.2
2
ghcr.io/stashed/stash-ui-server:v0.23.047cffbc65700
google.golang.org/grpc@v1.62.1
1.82.2
2
ghcr.io/voyagermesh/gateway:v1.8.24237fd16a3cb
google.golang.org/grpc@v1.81.1
1.82.2
2
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
google.golang.org/grpc@v1.67.1
1.82.2
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.