PT-2026-31732 · Cncf+1 · Helm+1

CVE-2026-35206

·

Published

2026-04-09

·

Updated

2026-08-10

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Helm versions 3.20.1 and earlier, and versions 4.1.3 and earlier
Description Helm, a package manager for Kubernetes Charts, is affected by an issue where a specially crafted Chart can cause the helm pull --untar command to write chart contents to an incorrect directory. Specifically, the command writes to the current working directory (or directories specified by the --destination and --untardir flags) instead of the expected chart-name-suffixed output directory. This occurs when processing a malicious chart via the helm pull --untar command.
Recommendations Update to Helm version 3.20.2 or later. Update to Helm version 4.1.4 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07256
BIT-HELM-2026-35206
CLEANSTART-2026-CL67452
CLEANSTART-2026-QU98532
CLEANSTART-2026-SI58032
CLEANSTART-2026-US10263
CLEANSTART-2026-XP87070
CVE-2026-35206
GHSA-HR2V-4R36-88HR
GO-2026-5435
OPENSUSE-SU-2026:10532-1
OPENSUSE-SU-2026:10538-1
OPENSUSE-SU-2026:20655-1
OPENSUSE-SU-2026:21551-1
SUSE-SU-2026:1483-1
SUSE-SU-2026:21434-1
SUSE-SU-2026:21461-1
SUSE-SU-2026:21628-1
SUSE-SU-2026:21635-1
SUSE-SU-2026:23216-1
SUSE-SU-2026:23227-1

Affected Products

Helm
Red Os