Improper input validation in Helm - CVE-2026-35206
Published: April 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to overwrite files in the target output directory.
The vulnerability exists due to improper input validation in Chart extraction logic when processing a specially crafted Chart with helm pull --untar. A remote attacker can supply a crafted Chart whose Chart.yaml name is . to overwrite files in the target output directory.
User interaction is required to pull and extract the crafted Chart.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
Containers Module
SUSE Package Hub 15
helm-debuginfo
helm
helm-bash-completion
helm-zsh-completion
helm-fish-completion
How to mitigate CVE-2026-35206
helm-debuginfo - update to 3.20.2-150000.1.71.2
helm - update to 3.20.2-150000.1.71.2
helm-bash-completion - update to 3.20.2-150000.1.71.2
helm-zsh-completion - update to 3.20.2-150000.1.71.2
helm-fish-completion - update to 3.20.2-150000.1.71.2