8.4
CVE-2026-35205
- EPSS 0.22%
- Veröffentlicht 09.04.2026 16:16:27
- Zuletzt bearbeitet 15.07.2026 02:20:41
- CVE-Watchlists
- Unerledigt
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.127 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| security-advisories@github.com | 8.4 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CWE-636 Not Failing Securely ('Failing Open')
When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.
https://github.com/helm/helm/releases/tag/v4.1.4
https://github.com/helm/helm/commit/05fa37973dc9e42b76e1d2883494c87174b6074f
https://helm.sh/docs/topics/provenance/#the-provenance-file
https://bugzilla.redhat.com/show_bug.cgi?id=2456927
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35205.json
https://access.redhat.com/errata/RHSA-2026:26441
https://github.com/helm/helm/security/advisories/GHSA-q5jf-9vfq-h4h7
https://access.redhat.com/security/cve/CVE-2026-35205