CVE-2026-35205
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
نوع الضعف
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
المنتجات المتأثرة
- helm helm
المراجع
- https://github.com/helm/helm/commit/05fa37973dc9e42b76e1d2883494c87174b6074f
- https://github.com/helm/helm/releases/tag/v4.1.4
- https://github.com/helm/helm/security/advisories/GHSA-q5jf-9vfq-h4h7
- https://helm.sh/docs/topics/provenance/#the-provenance-file
- https://access.redhat.com/errata/RHSA-2026:26441
- https://access.redhat.com/security/cve/CVE-2026-35205
اكتشف الثغرة قبل أن يكتشفها المهاجم.
سجّل الدخول عبر GitHub وشغّل أول تدقيق لك في أقل من دقيقة. الخطة المجانية لا تتطلب بطاقة ائتمان.