CVE-2026-35205 PUBLISHED

Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install

Assigner: GitHub_M
Reserved: 01.04.2026 Published: 09.04.2026 Updated: 09.04.2026

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor helm
Product helm
Versions
  • Version >= 4.0.0, < 4.1.4 is affected

References

Problem Types

  • CWE-636: Not Failing Securely ('Failing Open') CWE