CVE-2026-35205

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-09 16:16

Updated : 2026-07-15 02:20


NVD link : CVE-2026-35205

Mitre link : CVE-2026-35205

CVE.ORG link : CVE-2026-35205


JSON object : View

Products Affected

helm

  • helm
CWE
CWE-636

Not Failing Securely ('Failing Open')

CWE-347

Improper Verification of Cryptographic Signature