CVE-2026-35205
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
| CWE | CWE-636 |
| Vendor | helm |
| Product | helm |
| Published | Apr 9, 2026 |
| Last Updated | Jul 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for helm helm
Be the first to know when new high vulnerabilities affecting helm helm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
helm / helm
>= 4.0.0, < 4.1.4
References
github.com: https://github.com/helm/helm/security/advisories/GHSA-q5jf-9vfq-h4h7 github.com: https://github.com/helm/helm/commit/05fa37973dc9e42b76e1d2883494c87174b6074f github.com: https://github.com/helm/helm/releases/tag/v4.1.4 helm.sh: https://helm.sh/docs/topics/provenance/#the-provenance-file access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-35205 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2456927 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35205.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:26441