Vulnerabilities in helm
23 resultsCVE-2026-35206MEDIUMHelm Chart extraction output directory collapse via `Chart.yaml` name dot-segmentEPSS 0.2%CVE-2026-35205HIGHHelm's plugin verification fails open when .prov is missing, allowing unsigned plugin installEPSS 0.2%CVE-2026-35204HIGHHelm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directoryEPSS 0.2%