Improper input validation in Helm - CVE-2026-35206

 

Improper input validation in Helm - CVE-2026-35206

Published: April 10, 2026


Vulnerability identifier: #VU125751
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35206
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite files in the target output directory.

The vulnerability exists due to improper input validation in Chart extraction logic when processing a specially crafted Chart with helm pull --untar. A remote attacker can supply a crafted Chart whose Chart.yaml name is . to overwrite files in the target output directory.

User interaction is required to pull and extract the crafted Chart.


Affected software

Helm
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
Containers Module
SUSE Package Hub 15
helm-debuginfo
helm
helm-bash-completion
helm-zsh-completion
helm-fish-completion

How to mitigate CVE-2026-35206

Install security update from vendor's website.

Helm - addressed in versions 3.20.2, 4.1.4
helm-debuginfo - update to 3.20.2-150000.1.71.2
helm - update to 3.20.2-150000.1.71.2
helm-bash-completion - update to 3.20.2-150000.1.71.2
helm-zsh-completion - update to 3.20.2-150000.1.71.2
helm-fish-completion - update to 3.20.2-150000.1.71.2

External References

Related Security Bulletins