Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35206

Опубликовано: 09 апр. 2026
Источник: nvd
CVSS3: 4.4
EPSS Низкий

Описание

Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as given by the --destination and --untardir flags), rather than the expected output directory suffixed by the chart's name. This vulnerability is fixed in 3.20.2 and 4.1.4.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*
Версия до 3.20.2 (исключая)
cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.1.4 (исключая)

EPSS

Процентиль: 10%
0.00199
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.4
redhat
4 месяца назад

Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as given by the --destination and --untardir flags), rather than the expected output directory suffixed by the chart's name. This vulnerability is fixed in 3.20.2 and 4.1.4.

msrc
4 месяца назад

Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

CVSS3: 4.4
debian
4 месяца назад

Helm is a package manager for Charts for Kubernetes. In Helm versions ...

github
4 месяца назад

Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

CVSS3: 5.1
fstec
4 месяца назад

Уязвимость пакетного менеджера для Kubernetes Helm, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 10%
0.00199
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-22