<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:50:05 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02609</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02609</link>
      <description>bdu:2024-02609</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02609</guid>
    </item>
    <item>
      <title>BIT-helm-2024-26147 — Helm's Missing YAML Content Leads To Panic</title>
      <link>https://cve.radiocsirt.org/vuln/bit-helm-2024-26147</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: helm&lt;/p&gt;
&lt;p&gt;Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In the Helm SDK, this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation. This issue has been resolved in Helm v3.14.2. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: helm&lt;/p&gt;
&lt;p&gt;Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In the Helm SDK, this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation. This issue has been resolved in Helm v3.14.2. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-helm-2024-26147</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958</link>
      <description>certfr-2024-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958</guid>
    </item>
    <item>
      <title>EUVD-2026-158615</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-158615</link>
      <description>EUVD-2026-158615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-158615</guid>
    </item>
    <item>
      <title>fkie_cve-2024-26147</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26147</link>
      <description>&lt;p&gt;Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In the Helm SDK, this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation. This issue has been resolved in Helm v3.14.2. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In the Helm SDK, this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation. This issue has been resolved in Helm v3.14.2. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-26147</guid>
    </item>
    <item>
      <title>GHSA-r53h-jv2g-vpx6 — Helm's Missing YAML Content Leads To Panic</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r53h-jv2g-vpx6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: helm.sh/helm/v3&lt;/p&gt;
&lt;p&gt;A Helm contributor discovered uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm.&lt;/p&gt;
&lt;p&gt;In the Helm SDK this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been resolved in Helm v3.14.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem.&lt;/p&gt;
&lt;p&gt;If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;Helm&amp;#39;s security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document.&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Disclosed by Jakub Ciolek at AlphaSense.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: helm.sh/helm/v3&lt;/p&gt;
&lt;p&gt;A Helm contributor discovered uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm.&lt;/p&gt;
&lt;p&gt;In the Helm SDK this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been resolved in Helm v3.14.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem.&lt;/p&gt;
&lt;p&gt;If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;Helm&amp;#39;s security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document.&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Disclosed by Jakub Ciolek at AlphaSense.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r53h-jv2g-vpx6</guid>
    </item>
    <item>
      <title>gsd-2024-26147</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-26147</link>
      <description>gsd-2024-26147</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-26147</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-26147 — Helm's Missing YAML Content Leads To Panic</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-26147</link>
      <description>msrc_CVE-2024-26147</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-26147</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13708-1 — helm-3.14.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13708-1</link>
      <description>&lt;p&gt;helm-3.14.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;helm-3.14.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13708-1</guid>
    </item>
    <item>
      <title>RHSA-2024:1328 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.9.3 security and bug fix container updates</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1328</link>
      <description>&lt;p&gt;opentelemetry: DoS vulnerability in otelhttp opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics helm: Dependency management path traversal helm: Missing YAML Content Leads To Panic&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;opentelemetry: DoS vulnerability in otelhttp opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics helm: Dependency management path traversal helm: Missing YAML Content Leads To Panic&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1328</guid>
    </item>
    <item>
      <title>SUSE-RU-2024:4213-1 — Recommended update for helm</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2024:4213-1</link>
      <description>&lt;p&gt;Recommended update for helm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for helm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2024:4213-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-26147</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26147</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: helm, Ubuntu:18.04:LTS: helm, Ubuntu:20.04:LTS: helm, Ubuntu:22.04:LTS: helm, Ubuntu:24.04:LTS: helm, Ubuntu:25.10: helm, Ubuntu:26.04:LTS: helm&lt;/p&gt;
&lt;p&gt;Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In the Helm SDK, this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation. This issue has been resolved in Helm v3.14.2. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: helm, Ubuntu:18.04:LTS: helm, Ubuntu:20.04:LTS: helm, Ubuntu:22.04:LTS: helm, Ubuntu:24.04:LTS: helm, Ubuntu:25.10: helm, Ubuntu:26.04:LTS: helm&lt;/p&gt;
&lt;p&gt;Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all metadata a panic would occur in Helm. In the Helm SDK, this is found when using the `LoadIndexFile` or `DownloadIndexFile` functions in the `repo` package or the `LoadDir` function in the `plugin` package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation. This issue has been resolved in Helm v3.14.2. If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use `recover` to catch the panic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26147</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0641 — Red Hat Enterprise Linux (Advanced Cluster Management): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0641</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0641</guid>
    </item>
  </channel>
</rss>
