
CVE-2026-35205 Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is req… https://www.cve.org/CVERecord?id=CVE-2026-35205
Post summary
CVE-2026-35205 reveals that Helm 4.0.0‑4.1.3 can install plugins lacking provenance checks, compromising signature verification for Kubernetes charts.

