SUSE-SU-2026:22305-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622305-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22305-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:22305-1
Upstream
Related
Published
2026-06-21T00:45:47Z
Modified
2026-07-02T18:24:09Z
Summary
Security update for helm
Details

This update for helm fixes the following issue

  • CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598).

Changes for helm:

  • Update to version 3.21.1:
  • Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920
  • Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152
  • Bumped Go from 1.25 to 1.26 #32168
  • Dependency version updates
    • chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1
    • chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0
    • chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0
    • chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0
    • chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3
    • chore(deps): bump github.com/distribution/distribution/v3
    • chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32
    • chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0
    • chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13
    • chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0
    • chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0
    • chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0
References

Affected packages

SUSE:Linux Enterprise Server 16.0 / helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.21.1-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "helm":  "3.21.1-160000.1.1",
            "helm-bash-completion":  "3.21.1-160000.1.1",
            "helm-fish-completion":  "3.21.1-160000.1.1",
            "helm-zsh-completion":  "3.21.1-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22305-1.json"

SUSE:Linux Enterprise Server for SAP applications 16.0 / helm

Package

Name
helm
Purl
pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.21.1-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "helm":  "3.21.1-160000.1.1",
            "helm-bash-completion":  "3.21.1-160000.1.1",
            "helm-fish-completion":  "3.21.1-160000.1.1",
            "helm-zsh-completion":  "3.21.1-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22305-1.json"