CVE-2026-35205

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*

History

17 Apr 2026, 14:05

Type Values Removed Values Added
CPE cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Helm
Helm helm
References () https://github.com/helm/helm/commit/05fa37973dc9e42b76e1d2883494c87174b6074f - () https://github.com/helm/helm/commit/05fa37973dc9e42b76e1d2883494c87174b6074f - Patch
References () https://github.com/helm/helm/releases/tag/v4.1.4 - () https://github.com/helm/helm/releases/tag/v4.1.4 - Product, Release Notes
References () https://github.com/helm/helm/security/advisories/GHSA-q5jf-9vfq-h4h7 - () https://github.com/helm/helm/security/advisories/GHSA-q5jf-9vfq-h4h7 - Vendor Advisory, Mitigation
References () https://helm.sh/docs/topics/provenance/#the-provenance-file - () https://helm.sh/docs/topics/provenance/#the-provenance-file - Product

09 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 16:16

Updated : 2026-04-17 14:05


NVD link : CVE-2026-35205

Mitre link : CVE-2026-35205

CVE.ORG link : CVE-2026-35205


JSON object : View

Products Affected

helm

  • helm
CWE
CWE-636

Not Failing Securely ('Failing Open')