openSUSE-SU-2026:21983-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21983-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21983-1
Upstream
CVE (18)
Related
Published
2026-09-30T17:58:26Z
Modified
2026-10-01T17:30:06Z
Summary
Security update for helm
Details

This update for helm fixes the following issues:

  • CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265758).
  • CVE-2026-35204: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary file write via specially crafted plugin (bsc#1261939).
  • CVE-2026-35205: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary code execution due to insufficient plugin provenance verification (bsc#1261935).
  • CVE-2026-35206: github.com/helm/helm: Helm: Files written to unexpected directory via specially crafted Chart (bsc#1261938).
  • CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510).
  • CVE-2026-41888: github.com/distribution/distribution/v3: tag deletion bypasses the storage.delete.enabled configuration (bsc#1265428).
  • CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127).
  • CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).
  • CVE-2026-50163: oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks (bsc#1276327).
  • CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997).
  • CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1281426).
  • CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1281426).
  • CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025).
  • CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification bypass (bsc#1275024).
  • CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1281426).
  • CVE-2026-81871: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration (bsc#1281468).
  • CVE-2026-81872: go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission (bsc#1281469).
  • CVE-2026-85732: oras.land/oras-go/v2: blind SSRF via unvalidated Link header URL in pagination allows internal network probing (bsc#1281112).
  • gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514).
References

Affected packages

openSUSE:Leap 16.0 / helm

Package

Name
helm
Purl
pkg:rpm/opensuse/helm&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.3.0-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "helm":  "4.3.0-160000.1.1",
            "helm-bash-completion":  "4.3.0-160000.1.1",
            "helm-fish-completion":  "4.3.0-160000.1.1",
            "helm-zsh-completion":  "4.3.0-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21983-1.json"