CVE-2026-44543
HighAdvisory
Published 11 May 2026In the index since 8 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.7
- base score, highest
- EPSS
- 0.004
- 34th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 6
- of 17,781 indexed, latest versions
- Container images
- 4
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Local Path Provisioner Vulnerable to HelperPod Template Injection
Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 4 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.0.0-20240903135710-7a64e376245f, v0.0.0-20241007141825-c4fdcada94c2, v0.0.32+dirty, v0.0.35+dirty | 0.0.36 | 4 |
- OSV records
- GHSA-7fxv-8wr2-mfc4
- Also known as
- GO-2026-5218
Charts affected
6 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| local-path-provisionerclastixVerified publisher | 0.0.30 | 1 of 1See more | 1,208 |
| storage-local-pathcnapVerified publisher | 1.0.1 | 1 of 1See more | 752 |
| gnp-stackgnp-stack | 0.0.5 | 1 of 14See more | 7,659 |
| local-path-provisionerkir4hVerified publisher | 0.0.35 | 1 of 1See more | 752 |
| local-path-provisionermikejohVerified publisher | 0.0.29 | 1 of 1See more | 1,300 |
| local-path-provisionerth-chartsVerified publisher | 0.0.29 | 1 of 1See more | 1,300 |
Container images carrying it
4 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| rancher/ | 34ff0847cc47 | github.com/ | 0.0.36 | 2 |
| rancher/ | 9bebefa0b908 | github.com/ | 0.0.36 | 2 |
| rancher/ | 9289da488b07 | github.com/ | 0.0.36 | 1 |
| rancher/ | 9b9148811700 | github.com/ | 0.0.36 | 1 |