{"id":"openSUSE-SU-2026:21983-1","summary":"Security update for helm","details":"This update for helm fixes the following issues:\n\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1265758).\n- CVE-2026-35204: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary file write via specially crafted plugin\n  (bsc#1261939).\n- CVE-2026-35205: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary code execution due to insufficient plugin\n  provenance verification (bsc#1261935).\n- CVE-2026-35206: github.com/helm/helm: Helm: Files written to unexpected directory via specially crafted Chart\n  (bsc#1261938).\n- CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length\n  headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510).\n- CVE-2026-41888: github.com/distribution/distribution/v3: tag deletion bypasses the storage.delete.enabled\n  configuration (bsc#1265428).\n- CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to\n  exfiltrate credentials and refresh tokens (bsc#1270127).\n- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).\n- CVE-2026-50163: oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks (bsc#1276327).\n- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997).\n- CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1281426).\n- CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1281426).\n- CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025).\n- CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification bypass (bsc#1275024).\n- CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1281426).\n- CVE-2026-81871: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass\n  allows log telemetry interception and alteration (bsc#1281468).\n- CVE-2026-81872: go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission\n  (bsc#1281469).\n- CVE-2026-85732: oras.land/oras-go/v2: blind SSRF via unvalidated Link header URL in pagination allows internal network\n  probing (bsc#1281112).\n- gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation\n  (bsc#1276514).\n","modified":"2026-10-01T18:23:23.810629496Z","published":"2026-09-30T17:58:26Z","related":["CVE-2026-33814","CVE-2026-35204","CVE-2026-35205","CVE-2026-35206","CVE-2026-41178","CVE-2026-41888","CVE-2026-48978","CVE-2026-50151","CVE-2026-50163","CVE-2026-56852","CVE-2026-56854","CVE-2026-56855","CVE-2026-56864","CVE-2026-56865","CVE-2026-78662","CVE-2026-81871","CVE-2026-81872","CVE-2026-85732"],"upstream":["CVE-2026-33814","CVE-2026-35204","CVE-2026-35205","CVE-2026-35206","CVE-2026-41178","CVE-2026-41888","CVE-2026-48978","CVE-2026-50151","CVE-2026-50163","CVE-2026-56852","CVE-2026-56854","CVE-2026-56855","CVE-2026-56864","CVE-2026-56865","CVE-2026-78662","CVE-2026-81871","CVE-2026-81872","CVE-2026-85732"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261935"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261938"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265758"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270127"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271660"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271997"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275024"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275025"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276327"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276510"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281112"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281426"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281468"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35204"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35205"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35206"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41888"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50151"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50163"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56865"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81871"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-81872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85732"}],"affected":[{"package":{"name":"helm","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/helm&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"helm-zsh-completion":"4.3.0-160000.1.1","helm":"4.3.0-160000.1.1","helm-bash-completion":"4.3.0-160000.1.1","helm-fish-completion":"4.3.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21983-1.json"}}],"schema_version":"1.9.0"}