CVE-2026-35205
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
Faiblesse
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
Produits concernés
- helm helm
Références
- https://github.com/helm/helm/commit/05fa37973dc9e42b76e1d2883494c87174b6074f
- https://github.com/helm/helm/releases/tag/v4.1.4
- https://github.com/helm/helm/security/advisories/GHSA-q5jf-9vfq-h4h7
- https://helm.sh/docs/topics/provenance/#the-provenance-file
- https://access.redhat.com/errata/RHSA-2026:26441
- https://access.redhat.com/security/cve/CVE-2026-35205
Trouvez la faille avant un attaquant.
Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.