CVE-2026-35206Disclosure(helm / helm)

LOWCVSS 4.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as given by the --destination and --untardir flags), rather than the expected output directory suffixed by the chart's name. This vulnerability is fixed in 3.20.2 and 4.1.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • helm

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
helm

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-05-04: 1Technical Details · 2026-04-09: 1Technical Details · 2026-05-04: 104-0905-04
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-05-041
General1
Full discourse3 posts
  • SecureChap@SecureChap
    General

    Nineteen years separate the first cataloged package manager path traversal (CVE-2007-0469) from this year's rediscovery (CVE-2026-34591, CVE-2026-35206). Same bug class. Same archive-extraction primitive. Different ecosystem. A new survey by Nesbitt catalogs a dozen CWE patterns that hit npm, PyPI, RubyGems, Composer, Cargo, Go, Helm, NuGet, and Conda over and over. A few standouts: Argument injection into VCS tools - six separate CVEs in one tool alone across git, hg, and Perforce wrappers (CVE-2021-29472, CVE-2022-36069, CVE-2021-43809, CVE-2023-5752, CVE-2022-24440, plus one more). Integrity checks that fail open: CVE-2016-1252 (clearsigned parser accepted unsigned content), CVE-2022-31156 (sig check silently skipped on error), CVE-2022-46176 (missing SSH host key on git index clones). Dependency confusion was already CVE-2013-0334 - eight years before its 2021 fame. Terminal escape sequences in package metadata: at least nine CVEs across four ecosystems. CocoaPods CVE-2024-38368: an orphaned admin API was left in place for ten years, until a researcher used it to claim 1,800 packages. The thesis: knowledge doesn't transfer between projects. Every ecosystem rediscovers the same dozen bugs from scratch. http://nesbitt.io/2026/05/04/package-manager-cwes.html

    Post summary

    A survey article noting that many package managers repeatedly rediscover the same seven CVE classes, underscoring a lack of cross‑ecosystem knowledge transfer.

    0000043
    44 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35206 Helm is a package manager for Charts for Kubernetes. In Helm versions &lt;=3.20.1 and &lt;=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/… https://www.cve.org/CVERecord?id=CVE-2026-35206 ----- Traducción: CVE-2026-35206 Hel… http://infoflow.cloud`

    Post summary

    The entry announces CVE-2026-35206, detailing that specially crafted Helm charts trigger an exploit in older Helm releases; no PoC, exploit code, or patch information is disclosed.

    0000026
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35206 Helm is a package manager for Charts for Kubernetes. In Helm versions &lt;=3.20.1 and &lt;=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/… https://www.cve.org/CVERecord?id=CVE-2026-35206

    Post summary

    The text announces CVE‑2026‑35206, indicating that specially crafted Helm charts can trigger a problem in helm pull on affected versions.

    00000116
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphelmhelm---

Explore more