Vulnerability Description
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Helm | Helm | >= 4.0.0, < 4.1.4 |
Related Weaknesses (CWE)
References
- https://github.com/helm/helm/commit/05fa37973dc9e42b76e1d2883494c87174b6074fPatch
- https://github.com/helm/helm/releases/tag/v4.1.4ProductRelease Notes
- https://github.com/helm/helm/security/advisories/GHSA-q5jf-9vfq-h4h7Vendor AdvisoryMitigation
- https://helm.sh/docs/topics/provenance/#the-provenance-fileProduct
FAQ
What is CVE-2026-35205?
CVE-2026-35205 is a vulnerability with a CVSS score of 7.8 (HIGH). Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed...
How severe is CVE-2026-35205?
CVE-2026-35205 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-35205?
Check the references section above for vendor advisories and patch information. Affected products include: Helm Helm.