VYPR

rpm package

opensuse/helm&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/helm&distro=openSUSE%20Tumbleweed

Vulnerabilities (31)

  • CVE-2026-56852HigJul 21, 2026
    affected < 4.2.3-3.1fixed 4.2.3-3.1

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-50151HigJul 17, 2026
    affected < 4.2.3-2.1fixed 4.2.3-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST reques

  • CVE-2026-48978LowJul 17, 2026
    affected < 4.2.2-2.1fixed 4.2.2-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such a

  • CVE-2026-63308MedJul 17, 2026
    affected < 4.2.3-4.1fixed 4.2.3-4.1

    Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can includ

  • CVE-2026-39821CriMay 22, 2026
    affected < 4.2.0-3.1fixed 4.2.0-3.1

    The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program

  • CVE-2026-41888MedMay 14, 2026
    affected < 4.2.0-1.1fixed 4.2.0-1.1

    Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2//manifests/ endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even w

  • CVE-2026-33814HigMay 7, 2026
    affected < 4.2.0-2.1fixed 4.2.0-2.1

    When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

  • CVE-2026-35206MedApr 9, 2026
    affected < 4.1.4-2.1fixed 4.1.4-2.1

    Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working di

  • CVE-2026-35205HigApr 9, 2026
    affected < 4.1.4-2.1fixed 4.1.4-2.1

    Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.

  • CVE-2026-35204HigApr 9, 2026
    affected < 4.1.4-1.1fixed 4.1.4-1.1

    Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Hel

  • CVE-2025-58190MedFeb 5, 2026
    affected < 3.19.1-1.1fixed 3.19.1-1.1

    The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

  • CVE-2025-47911MedFeb 5, 2026
    affected < 3.19.1-1.1fixed 3.19.1-1.1

    The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

  • CVE-2025-55199MedAug 14, 2025
    affected < 4.1.1-3.1fixed 4.1.1-3.1

    Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been resolved in Helm 3.18.5. A work

  • CVE-2025-53547HigJul 8, 2025
    affected < 3.18.4-1.1fixed 3.18.4-1.1

    Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a Chart.lo

  • CVE-2025-22872MedApr 16, 2025
    affected < 3.18.3-1.1fixed 3.18.3-1.1

    The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can resul

  • CVE-2025-22870MedMar 12, 2025
    affected < 3.17.2-1.1fixed 3.17.2-1.1

    Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

  • CVE-2024-45338MedDec 18, 2024
    affected < 3.17.0-2.1fixed 3.17.0-2.1

    An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

  • CVE-2024-45337CriDec 12, 2024
    affected < 3.16.4-1.1fixed 3.16.4-1.1

    Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that

  • CVE-2024-26147HigFeb 21, 2024
    affected < 3.14.2-1.1fixed 3.14.2-1.1

    Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all m

  • CVE-2024-25620MedFeb 15, 2024
    affected < 3.14.2-2.1fixed 3.14.2-2.1

    Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file includes a relative path change, the chart would be saved outside its expected direct

Page 1 of 2