CVE-2026-35205: Helm
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
Affected products
- Helm Helm: from 4.0.0, before 4.1.4 (fixed in 4.1.4)
Published 2026-04-09. Last modified 2026-07-15.