{"id":"SUSE-SU-2026:23546-1","summary":"Security update for helm","details":"This update for helm fixes the following issues:\n\n- CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization\n  policies via mixed-case or canonical-case header matches (bsc#1278270).\n- CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273).\n- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS\n  servers (bsc#1278688).\n","modified":"2026-09-29T18:23:51.076726231Z","published":"2026-09-09T12:04:21Z","related":["CVE-2026-84303","CVE-2026-84304","CVE-2026-84445"],"upstream":["CVE-2026-84303","CVE-2026-84304","CVE-2026-84445"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623546-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278270"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278273"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278688"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84304"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84445"}],"affected":[{"package":{"name":"helm","ecosystem":"SUSE:Linux Micro 6.0","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Micro%206.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.21.3-3.1"}]}],"ecosystem_specific":{"binaries":[{"helm-bash-completion":"3.21.3-3.1","helm":"3.21.3-3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23546-1.json"}}],"schema_version":"1.9.0"}