CVE-2026-35206
MediumAdvisory
Published 10 Apr 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.8
- base score, highest
- EPSS
- 0.002
- 10th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 201
- of 17,787 indexed, latest versions
- Container images
- 210
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Carried by container images the latest versions of 201 of 17,787 indexed charts deploy, on 210 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| helm.sh/ | v0.0.0-20221012195806-9f88ccb6aee4, v0.0.0-20221214143859-835b7334cfe2, v0.0.0-20230113165805-472c5736ab01, v0.0.0-20230308205603-912ebc1cd10d+80 more | 3.20.2 | 208 |
| helm.sh/ | v4.0.0-20250324191910-0199b748aaea, v4.1.0, v4.1.3 | 4.1.4 | 5 |
- OSV records
- GHSA-hr2v-4r36-88hr
- Also known as
- BIT-helm-2026-35206, GO-2026-5435
Charts affected
201 by stars
Container images carrying it
210 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 0bbe8b451fa3 | helm.sh/ | 3.20.2 | 1 |
| quay.io/ | 6ff40fa6257f | helm.sh/ | 3.20.2 | 1 |
| quay.io/ | bca5dfcc67ca | helm.sh/ | 3.20.2 | 1 |
| quay.io/ | 6ba82beff18e | helm.sh/ | 3.20.2 | 1 |
| quay.io/ | 5b62aaade3c9 | helm.sh/ | 3.20.2 | 1 |
| quay.io/ | 9a6c84560d44 | helm.sh/ | 3.20.2 | 1 |
| registry.gitlab.com/ | 80ef8ceffc92 | helm.sh/ | 3.20.2 | 1 |
| registry.gitlab.com/ | 36b19b72120e | helm.sh/ | 3.20.2 | 1 |
| registry.gitlab.com/ | 9b9d1ed86b6a | helm.sh/ | 3.20.2 | 1 |
| registry.gitlab.com/ | 301847adfe16 | helm.sh/ | 3.20.2 | 1 |