{"id":"SUSE-SU-2026:23456-1","summary":"Security update for helm","details":"This update for helm fixes the following issues:\n\n- CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST\n  request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277949).\n- CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length\n  headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510).\n- CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to\n  exfiltrate credentials and refresh tokens (bsc#1270127).\n- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).\n- CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic\n  (bsc#1272402).\n- gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation\n  (bsc#1276514).\n","modified":"2026-09-14T18:23:33.959562741Z","published":"2026-09-04T08:39:53Z","related":["CVE-2026-37236","CVE-2026-41178","CVE-2026-48978","CVE-2026-50151","CVE-2026-63308"],"upstream":["CVE-2026-37236","CVE-2026-41178","CVE-2026-48978","CVE-2026-50151","CVE-2026-63308"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623456-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270127"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271660"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272402"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276510"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277949"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-37236"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50151"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63308"}],"affected":[{"package":{"name":"c-ares","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.34.8-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libcares2":"1.34.8-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23456-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Micro 6.0","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Micro%206.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.21.3-2.1"}]}],"ecosystem_specific":{"binaries":[{"helm":"3.21.3-2.1","helm-bash-completion":"3.21.3-2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23456-1.json"}}],"schema_version":"1.9.0"}