๐Ÿ” CVE Alert

CVE-2026-35206

UNKNOWN 0.0

Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
2th

Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as given by the --destination and --untardir flags), rather than the expected output directory suffixed by the chart's name. This vulnerability is fixed in 3.20.2 and 4.1.4.

CWE CWE-22
Vendor helm
Product helm
Published Apr 9, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for helm helm

Be the first to know when new unknown vulnerabilities affecting helm helm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

helm / helm
>= 4.0.0, < 4.1.4 < 3.20.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/helm/helm/security/advisories/GHSA-hr2v-4r36-88hr github.com: https://github.com/helm/helm/commit/4e7994d4467182f535b6797c94b5b0e994a91436 github.com: https://github.com/helm/helm/releases/tag/v4.1.4