Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hr2v-4r36-88hr | Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment |
Thu, 16 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* |
Tue, 14 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Helm
Helm helm |
|
| Vendors & Products |
Helm
Helm helm |
Thu, 09 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as given by the --destination and --untardir flags), rather than the expected output directory suffixed by the chart's name. This vulnerability is fixed in 3.20.2 and 4.1.4. | |
| Title | Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-14T14:45:12.096Z
Reserved: 2026-04-01T18:48:58.937Z
Link: CVE-2026-35206
Updated: 2026-04-14T14:45:08.743Z
Status : Analyzed
Published: 2026-04-09T21:16:09.993
Modified: 2026-04-16T20:36:08.770
Link: CVE-2026-35206
OpenCVE Enrichment
Updated: 2026-04-10T09:29:07Z
Github GHSA