CVE-2026-35205: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary code execution due to insufficient plugin
provenance verification (bsc#1261935).
CVE-2026-35206: github.com/helm/helm: Helm: Files written to unexpected directory via specially crafted Chart
(bsc#1261938).
CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length
headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510).
CVE-2026-41888: github.com/distribution/distribution/v3: tag deletion bypasses the storage.delete.enabled
configuration (bsc#1265428).
CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to
exfiltrate credentials and refresh tokens (bsc#1270127).
CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).
CVE-2026-50163: oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks (bsc#1276327).
CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997).
CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1281426).
CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1281426).
CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025).