Vulnerability Description
Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as given by the --destination and --untardir flags), rather than the expected output directory suffixed by the chart's name. This vulnerability is fixed in 3.20.2 and 4.1.4.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Helm | Helm | < 3.20.2 |
Related Weaknesses (CWE)
References
- https://github.com/helm/helm/commit/4e7994d4467182f535b6797c94b5b0e994a91436Patch
- https://github.com/helm/helm/releases/tag/v4.1.4ProductRelease Notes
- https://github.com/helm/helm/security/advisories/GHSA-hr2v-4r36-88hrMitigationVendor Advisory
FAQ
What is CVE-2026-35206?
CVE-2026-35206 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's co...
How severe is CVE-2026-35206?
CVE-2026-35206 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-35206?
Check the references section above for vendor advisories and patch information. Affected products include: Helm Helm.