Skip to content

v0.7.0 ships Helm 3.20.0 which is vulnerable to CVE-2026-35206 #424

Description

@Division-x

CVE-2026-35206 affects Helm <= 3.20.1 and <= 4.1.3. When a specially crafted chart is pulled with helm pull --untar, its contents land directly in the output directory instead of a subdirectory named after the chart, which can clobber whatever is already there. Fixed in 3.20.2 and 4.1.4.

as per the title: rancher/shell:v0.7.0 ships 3.20.0-rancher1, putting it in the vulnerable range.

Request:

bump the Helm version in release/v2.14 and release/v2.13 branches to >= 3.20.2 to cover CVE-2026-35206.

References:

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No fields configured for Bug.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions