OPENSUSE-SU-2026:21983-1

Vulnerability from csaf_opensuse - Published: 2026-09-30 17:58 - Updated: 2026-10-01 16:39
Summary
Security update for helm
Severity
Important
Notes
Title of the patch: Security update for helm
Description of the patch: This update for helm fixes the following issues: - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265758). - CVE-2026-35204: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary file write via specially crafted plugin (bsc#1261939). - CVE-2026-35205: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary code execution due to insufficient plugin provenance verification (bsc#1261935). - CVE-2026-35206: github.com/helm/helm: Helm: Files written to unexpected directory via specially crafted Chart (bsc#1261938). - CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510). - CVE-2026-41888: github.com/distribution/distribution/v3: tag deletion bypasses the storage.delete.enabled configuration (bsc#1265428). - CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). - CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660). - CVE-2026-50163: oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks (bsc#1276327). - CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997). - CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1281426). - CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1281426). - CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025). - CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification bypass (bsc#1275024). - CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1281426). - CVE-2026-81871: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration (bsc#1281468). - CVE-2026-81872: go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission (bsc#1281469). - CVE-2026-85732: oras.land/oras-go/v2: blind SSRF via unvalidated Link header URL in pagination allows internal network probing (bsc#1281112). - gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514).
Patchnames: openSUSE-Leap-16.0-1794
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Affected products
Product Identifier Version Remediation
Unresolved product id: openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64 —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64 —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch —
Vendor Fix
Threats
Impact important
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact important
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact important
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact moderate
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact moderate
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact moderate
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact moderate
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact important
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact important
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact moderate
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact important
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact important
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact moderate
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact important
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact important
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact moderate
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact moderate
Affected products
Recommended 7 products, the same list as for CVE-2026-33814
Threats
Impact moderate
References
URL Category
https://www.suse.com/support/security/rating/ external
https://ftp.suse.com/pub/projects/security/csaf/o… self
https://bugzilla.suse.com/1261935 self
https://bugzilla.suse.com/1261938 self
https://bugzilla.suse.com/1261939 self
https://bugzilla.suse.com/1265428 self
https://bugzilla.suse.com/1265758 self
https://bugzilla.suse.com/1270127 self
https://bugzilla.suse.com/1271660 self
https://bugzilla.suse.com/1271997 self
https://bugzilla.suse.com/1275024 self
https://bugzilla.suse.com/1275025 self
https://bugzilla.suse.com/1276327 self
https://bugzilla.suse.com/1276510 self
https://bugzilla.suse.com/1276514 self
https://bugzilla.suse.com/1281112 self
https://bugzilla.suse.com/1281426 self
https://bugzilla.suse.com/1281468 self
https://bugzilla.suse.com/1281469 self
https://www.suse.com/security/cve/CVE-2026-33814/ self
https://www.suse.com/security/cve/CVE-2026-35204/ self
https://www.suse.com/security/cve/CVE-2026-35205/ self
https://www.suse.com/security/cve/CVE-2026-35206/ self
https://www.suse.com/security/cve/CVE-2026-41178/ self
https://www.suse.com/security/cve/CVE-2026-41888/ self
https://www.suse.com/security/cve/CVE-2026-48978/ self
https://www.suse.com/security/cve/CVE-2026-50151/ self
https://www.suse.com/security/cve/CVE-2026-50163/ self
https://www.suse.com/security/cve/CVE-2026-56852/ self
https://www.suse.com/security/cve/CVE-2026-56854/ self
https://www.suse.com/security/cve/CVE-2026-56855/ self
https://www.suse.com/security/cve/CVE-2026-56864/ self
https://www.suse.com/security/cve/CVE-2026-56865/ self
https://www.suse.com/security/cve/CVE-2026-78662/ self
https://www.suse.com/security/cve/CVE-2026-81871/ self
https://www.suse.com/security/cve/CVE-2026-81872/ self
https://www.suse.com/security/cve/CVE-2026-85732/ self
https://www.suse.com/security/cve/CVE-2026-33814 external
https://bugzilla.suse.com/1264506 external
https://bugzilla.suse.com/1268758 external
https://www.suse.com/security/cve/CVE-2026-35204 external
https://bugzilla.suse.com/1261939 external
https://www.suse.com/security/cve/CVE-2026-35205 external
https://bugzilla.suse.com/1261934 external
https://www.suse.com/security/cve/CVE-2026-35206 external
https://bugzilla.suse.com/1261938 external
https://www.suse.com/security/cve/CVE-2026-41178 external
https://bugzilla.suse.com/1276509 external
https://www.suse.com/security/cve/CVE-2026-41888 external
https://bugzilla.suse.com/1265422 external
https://www.suse.com/security/cve/CVE-2026-48978 external
https://bugzilla.suse.com/1270126 external
https://www.suse.com/security/cve/CVE-2026-50151 external
https://bugzilla.suse.com/1271461 external
https://www.suse.com/security/cve/CVE-2026-50163 external
https://bugzilla.suse.com/1271462 external
https://www.suse.com/security/cve/CVE-2026-56852 external
https://bugzilla.suse.com/1271661 external
https://bugzilla.suse.com/1280553 external
https://www.suse.com/security/cve/CVE-2026-56854 external
https://bugzilla.suse.com/1278446 external
https://bugzilla.suse.com/1280553 external
https://www.suse.com/security/cve/CVE-2026-56855 external
https://bugzilla.suse.com/1278446 external
https://bugzilla.suse.com/1280553 external
https://www.suse.com/security/cve/CVE-2026-56864 external
https://bugzilla.suse.com/1275025 external
https://www.suse.com/security/cve/CVE-2026-56865 external
https://bugzilla.suse.com/1275024 external
https://www.suse.com/security/cve/CVE-2026-78662 external
https://bugzilla.suse.com/1278446 external
https://bugzilla.suse.com/1280553 external
https://www.suse.com/security/cve/CVE-2026-81871 external
https://bugzilla.suse.com/1281466 external
https://www.suse.com/security/cve/CVE-2026-81872 external
https://bugzilla.suse.com/1281467 external
https://www.suse.com/security/cve/CVE-2026-85732 external
https://bugzilla.suse.com/1281108 external

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Security update for helm",
        "title": "Title of the patch"
      },
      {
        "category": "description",
        "text": "This update for helm fixes the following issues:\n\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1265758).\n- CVE-2026-35204: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary file write via specially crafted plugin\n  (bsc#1261939).\n- CVE-2026-35205: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary code execution due to insufficient plugin\n  provenance verification (bsc#1261935).\n- CVE-2026-35206: github.com/helm/helm: Helm: Files written to unexpected directory via specially crafted Chart\n  (bsc#1261938).\n- CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length\n  headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510).\n- CVE-2026-41888: github.com/distribution/distribution/v3: tag deletion bypasses the storage.delete.enabled\n  configuration (bsc#1265428).\n- CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to\n  exfiltrate credentials and refresh tokens (bsc#1270127).\n- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).\n- CVE-2026-50163: oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks (bsc#1276327).\n- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997).\n- CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1281426).\n- CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1281426).\n- CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025).\n- CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification bypass (bsc#1275024).\n- CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1281426).\n- CVE-2026-81871: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass\n  allows log telemetry interception and alteration (bsc#1281468).\n- CVE-2026-81872: go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission\n  (bsc#1281469).\n- CVE-2026-85732: oras.land/oras-go/v2: blind SSRF via unvalidated Link header URL in pagination allows internal network\n  probing (bsc#1281112).\n- gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation\n  (bsc#1276514).\n",
        "title": "Description of the patch"
      },
      {
        "category": "details",
        "text": "openSUSE-Leap-16.0-1794",
        "title": "Patchnames"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "SUSE ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "self",
        "summary": "URL of this CSAF notice",
        "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_21983-1.json"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1261935",
        "url": "https://bugzilla.suse.com/1261935"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1261938",
        "url": "https://bugzilla.suse.com/1261938"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1261939",
        "url": "https://bugzilla.suse.com/1261939"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1265428",
        "url": "https://bugzilla.suse.com/1265428"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1265758",
        "url": "https://bugzilla.suse.com/1265758"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1270127",
        "url": "https://bugzilla.suse.com/1270127"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1271660",
        "url": "https://bugzilla.suse.com/1271660"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1271997",
        "url": "https://bugzilla.suse.com/1271997"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275024",
        "url": "https://bugzilla.suse.com/1275024"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275025",
        "url": "https://bugzilla.suse.com/1275025"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1276327",
        "url": "https://bugzilla.suse.com/1276327"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1276510",
        "url": "https://bugzilla.suse.com/1276510"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1276514",
        "url": "https://bugzilla.suse.com/1276514"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1281112",
        "url": "https://bugzilla.suse.com/1281112"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1281426",
        "url": "https://bugzilla.suse.com/1281426"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1281468",
        "url": "https://bugzilla.suse.com/1281468"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1281469",
        "url": "https://bugzilla.suse.com/1281469"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-33814 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-33814/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-35204 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-35204/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-35205 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-35205/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-35206 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-35206/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-41178 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-41178/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-41888 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-41888/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-48978 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-48978/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-50151 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-50151/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-50163 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-50163/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56852 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56852/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56854 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56854/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56855 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56855/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56864 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56864/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56865 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56865/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-78662 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-78662/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-81871 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-81871/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-81872 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-81872/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-85732 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-85732/"
      }
    ],
    "title": "Security update for helm",
    "tracking": {
      "current_release_date": "2026-10-01T16:39:39Z",
      "generator": {
        "date": "2026-09-30T17:58:26Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf.pl",
          "version": "1"
        }
      },
      "id": "openSUSE-SU-2026:21983-1",
      "initial_release_date": "2026-09-30T17:58:26Z",
      "revision_history": [
        {
          "date": "2026-09-30T17:58:26Z",
          "number": "1",
          "summary": "Current version"
        },
        {
          "date": "2026-10-01T16:39:39Z",
          "number": "2",
          "summary": "unknown changes"
        }
      ],
      "status": "final",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "helm-0:4.3.0-160000.1.1.aarch64",
                "product": {
                  "name": "helm-0:4.3.0-160000.1.1.aarch64",
                  "product_id": "helm-0:4.3.0-160000.1.1.aarch64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:helm:helm:4.3.0:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/helm@4.3.0-160000.1.1?arch=aarch64\u0026upstream=helm-0:4.3.0-160000.1.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "helm-bash-completion-0:4.3.0-160000.1.1.noarch",
                "product": {
                  "name": "helm-bash-completion-0:4.3.0-160000.1.1.noarch",
                  "product_id": "helm-bash-completion-0:4.3.0-160000.1.1.noarch",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:helm:helm:4.3.0:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/helm-bash-completion@4.3.0-160000.1.1?arch=noarch\u0026upstream=helm-0:4.3.0-160000.1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "helm-fish-completion-0:4.3.0-160000.1.1.noarch",
                "product": {
                  "name": "helm-fish-completion-0:4.3.0-160000.1.1.noarch",
                  "product_id": "helm-fish-completion-0:4.3.0-160000.1.1.noarch",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:helm:helm:4.3.0:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/helm-fish-completion@4.3.0-160000.1.1?arch=noarch\u0026upstream=helm-0:4.3.0-160000.1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "helm-zsh-completion-0:4.3.0-160000.1.1.noarch",
                "product": {
                  "name": "helm-zsh-completion-0:4.3.0-160000.1.1.noarch",
                  "product_id": "helm-zsh-completion-0:4.3.0-160000.1.1.noarch",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:helm:helm:4.3.0:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/helm-zsh-completion@4.3.0-160000.1.1?arch=noarch\u0026upstream=helm-0:4.3.0-160000.1.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "helm-0:4.3.0-160000.1.1.ppc64le",
                "product": {
                  "name": "helm-0:4.3.0-160000.1.1.ppc64le",
                  "product_id": "helm-0:4.3.0-160000.1.1.ppc64le",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:helm:helm:4.3.0:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/helm@4.3.0-160000.1.1?arch=ppc64le\u0026upstream=helm-0:4.3.0-160000.1.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "ppc64le"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "helm-0:4.3.0-160000.1.1.s390x",
                "product": {
                  "name": "helm-0:4.3.0-160000.1.1.s390x",
                  "product_id": "helm-0:4.3.0-160000.1.1.s390x",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:helm:helm:4.3.0:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/helm@4.3.0-160000.1.1?arch=s390x\u0026upstream=helm-0:4.3.0-160000.1.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "s390x"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "helm-0:4.3.0-160000.1.1.x86_64",
                "product": {
                  "name": "helm-0:4.3.0-160000.1.1.x86_64",
                  "product_id": "helm-0:4.3.0-160000.1.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:helm:helm:4.3.0:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/helm@4.3.0-160000.1.1?arch=x86_64\u0026upstream=helm-0:4.3.0-160000.1.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "openSUSE Leap 16.0",
                "product": {
                  "name": "openSUSE Leap 16.0",
                  "product_id": "openSUSE Leap 16.0"
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "helm-0:4.3.0-160000.1.1.aarch64 as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64"
        },
        "product_reference": "helm-0:4.3.0-160000.1.1.aarch64",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "helm-0:4.3.0-160000.1.1.ppc64le as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le"
        },
        "product_reference": "helm-0:4.3.0-160000.1.1.ppc64le",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "helm-0:4.3.0-160000.1.1.s390x as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x"
        },
        "product_reference": "helm-0:4.3.0-160000.1.1.s390x",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "helm-0:4.3.0-160000.1.1.x86_64 as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64"
        },
        "product_reference": "helm-0:4.3.0-160000.1.1.x86_64",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "helm-bash-completion-0:4.3.0-160000.1.1.noarch as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch"
        },
        "product_reference": "helm-bash-completion-0:4.3.0-160000.1.1.noarch",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "helm-fish-completion-0:4.3.0-160000.1.1.noarch as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch"
        },
        "product_reference": "helm-fish-completion-0:4.3.0-160000.1.1.noarch",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "helm-zsh-completion-0:4.3.0-160000.1.1.noarch as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        },
        "product_reference": "helm-zsh-completion-0:4.3.0-160000.1.1.noarch",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-33814",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-33814"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-33814",
          "url": "https://www.suse.com/security/cve/CVE-2026-33814"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1264506 for CVE-2026-33814",
          "url": "https://bugzilla.suse.com/1264506"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1268758 for CVE-2026-33814",
          "url": "https://bugzilla.suse.com/1268758"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-33814"
    },
    {
      "cve": "CVE-2026-35204",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-35204"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not include a version: field containing POSIX dot-dot path separators ie. \"/../\". This vulnerability is fixed in 4.1.4.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-35204",
          "url": "https://www.suse.com/security/cve/CVE-2026-35204"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1261939 for CVE-2026-35204",
          "url": "https://bugzilla.suse.com/1261939"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-35204"
    },
    {
      "cve": "CVE-2026-35205",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-35205"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-35205",
          "url": "https://www.suse.com/security/cve/CVE-2026-35205"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1261934 for CVE-2026-35205",
          "url": "https://bugzilla.suse.com/1261934"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-35205"
    },
    {
      "cve": "CVE-2026-35206",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-35206"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Helm is a package manager for Charts for Kubernetes. In Helm versions \u003c=3.20.1 and \u003c=4.1.3, a specially crafted Chart will cause helm pull --untar  [chart URL | repo/chartname] to write the Chart\u0027s contents to the immediate output directory (as defaulted to the current working directory; or as given by the --destination and --untardir flags), rather than the expected output directory suffixed by the chart\u0027s name. This vulnerability is fixed in 3.20.2 and 4.1.4.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-35206",
          "url": "https://www.suse.com/security/cve/CVE-2026-35206"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1261938 for CVE-2026-35206",
          "url": "https://bugzilla.suse.com/1261938"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-35206"
    },
    {
      "cve": "CVE-2026-41178",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-41178"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the issue.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-41178",
          "url": "https://www.suse.com/security/cve/CVE-2026-41178"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276509 for CVE-2026-41178",
          "url": "https://bugzilla.suse.com/1276509"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-41178"
    },
    {
      "cve": "CVE-2026-41888",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-41888"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/\u003cname\u003e/manifests/\u003ctag\u003e endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-41888",
          "url": "https://www.suse.com/security/cve/CVE-2026-41888"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1265422 for CVE-2026-41888",
          "url": "https://bugzilla.suse.com/1265422"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-41888"
    },
    {
      "cve": "CVE-2026-48978",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-48978"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry\u0027s WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-48978",
          "url": "https://www.suse.com/security/cve/CVE-2026-48978"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1270126 for CVE-2026-48978",
          "url": "https://bugzilla.suse.com/1270126"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.1,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-48978"
    },
    {
      "cve": "CVE-2026-50151",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-50151"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller\u0027s credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-50151",
          "url": "https://www.suse.com/security/cve/CVE-2026-50151"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271461 for CVE-2026-50151",
          "url": "https://bugzilla.suse.com/1271461"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-50151"
    },
    {
      "cve": "CVE-2026-50163",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-50163"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link(\"victim.secret\", \"\u003cextract_base\u003e/payload.tar.gz/evil_cwd_link\") to resolve header.Linkname against the process current working directory for a Typeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link and Linkname=\"victim.secret\" with io.deis.oras.content.unpack: \"true\", which can expose or tamper with files such as .env, .git/config, .aws/credentials, and ~/.ssh/config. This issue is fixed in version 2.6.2.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-50163",
          "url": "https://www.suse.com/security/cve/CVE-2026-50163"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271462 for CVE-2026-50163",
          "url": "https://bugzilla.suse.com/1271462"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-50163"
    },
    {
      "cve": "CVE-2026-56852",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56852"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56852",
          "url": "https://www.suse.com/security/cve/CVE-2026-56852"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271661 for CVE-2026-56852",
          "url": "https://bugzilla.suse.com/1271661"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280553 for CVE-2026-56852",
          "url": "https://bugzilla.suse.com/1280553"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-56852"
    },
    {
      "cve": "CVE-2026-56854",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56854"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client\u0027s remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56854",
          "url": "https://www.suse.com/security/cve/CVE-2026-56854"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278446 for CVE-2026-56854",
          "url": "https://bugzilla.suse.com/1278446"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280553 for CVE-2026-56854",
          "url": "https://bugzilla.suse.com/1280553"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-56854"
    },
    {
      "cve": "CVE-2026-56855",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56855"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56855",
          "url": "https://www.suse.com/security/cve/CVE-2026-56855"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278446 for CVE-2026-56855",
          "url": "https://bugzilla.suse.com/1278446"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280553 for CVE-2026-56855",
          "url": "https://bugzilla.suse.com/1280553"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-56855"
    },
    {
      "cve": "CVE-2026-56864",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56864"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected:   rm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56864",
          "url": "https://www.suse.com/security/cve/CVE-2026-56864"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275025 for CVE-2026-56864",
          "url": "https://bugzilla.suse.com/1275025"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-56864"
    },
    {
      "cve": "CVE-2026-56865",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56865"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected:   rm -r go.sum go.work.sum vendor/ \u0026\u0026 go mod tidy",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56865",
          "url": "https://www.suse.com/security/cve/CVE-2026-56865"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275024 for CVE-2026-56865",
          "url": "https://bugzilla.suse.com/1275024"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-56865"
    },
    {
      "cve": "CVE-2026-78662",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-78662"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Previously, a channel registered in the mux\u0027s chanList is not usable until it is established. A malicious peer was able flood the channel\u0027s incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-78662",
          "url": "https://www.suse.com/security/cve/CVE-2026-78662"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278446 for CVE-2026-78662",
          "url": "https://bugzilla.suse.com/1278446"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280553 for CVE-2026-78662",
          "url": "https://bugzilla.suse.com/1280553"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-78662"
    },
    {
      "cve": "CVE-2026-81871",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-81871"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS into cfg.tlsCfg, but newGRPCDialOptions does not apply cfg.tlsCfg when creating gRPC transport credentials. The environment-only TLS path instead uses credentials.NewTLS with system roots and no configured client certificate, bypassing intended private CA pinning and mutual TLS unless the application also supplies WithTLSCredentials. A network attacker able to intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. This issue is fixed in version 0.21.0.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-81871",
          "url": "https://www.suse.com/security/cve/CVE-2026-81871"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1281466 for CVE-2026-81871",
          "url": "https://bugzilla.suse.com/1281466"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-81871"
    },
    {
      "cve": "CVE-2026-81872",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-81872"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer while the exporter is backpressured. NewBatchingProcessor wraps the exporter with newBufferExporter(exporter, 1), and the poll loop calls queue.TryDequeue and bufferExporter.EnqueueExport before immediately signaling pollTrigger whenever the queue remains at or above batchSize. Because a failed nonblocking EnqueueExport leaves the queue length unchanged, the processor repeatedly retries without waiting for its ticker, exhausting CPU and degrading or denying service in the embedding process. This issue is fixed in version 0.21.0.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-81872",
          "url": "https://www.suse.com/security/cve/CVE-2026-81872"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1281467 for CVE-2026-81872",
          "url": "https://bugzilla.suse.com/1281467"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-81872"
    },
    {
      "cve": "CVE-2026-85732",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-85732"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. Tags, Referrers, and Repositories pagination operations then issue a GET request to the attacker-selected URL from the victim\u0027s network, allowing blind server-side request forgery against internal services. The response body is not returned to the attacker, but timing and error differences can reveal service reachability, and credentials may be attached when the credential store has an entry for the target host. Exploitation requires a victim to perform a pagination-based listing operation against a malicious registry. The maintainer identifies this report as a duplicate of GHSA-3hr5-mjrr-hfjh and states that remediation is consolidated in that earlier advisory. The consolidated issue is fixed in version 2.6.2.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
          "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
          "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
          "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-85732",
          "url": "https://www.suse.com/security/cve/CVE-2026-85732"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1281108 for CVE-2026-85732",
          "url": "https://bugzilla.suse.com/1281108"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.aarch64",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.ppc64le",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.s390x",
            "openSUSE Leap 16.0:helm-0:4.3.0-160000.1.1.x86_64",
            "openSUSE Leap 16.0:helm-bash-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-fish-completion-0:4.3.0-160000.1.1.noarch",
            "openSUSE Leap 16.0:helm-zsh-completion-0:4.3.0-160000.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T17:58:26Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-85732"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…