Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for helm ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21331-1 Rating: low References: * bsc#1270127 Cross-References: * CVE-2026-48978 CVSS scores: * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for helm fixes the following issue - CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). Changes for helm: - Update to version 3.21.2. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1235=1 Package List: - openSUSE Leap 16.0: helm-3.21.2-160000.2.1 helm-bash-completion-3.21.2-160000.2.1 helm-fish-completion-3.21.2-160000.2.1 helm-zsh-completion-3.21.2-160000.2.1 References: * https://www.suse.com/security/cve/CVE-2026-48978.html . Learn about the low-severity update for openSUSE helm addressing credential exfiltration vulnerabilities and a bug fix.. openSUSE update, helm security, credential hijacking, security patch. . Severity: Low. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for helm Announcement ID: SUSE-SU-2026:2823-1 Release Date: 2026-07-09T18:14:15Z Rating: important References: * bsc#1266598 * bsc#1270127 Cross-References: * CVE-2026-39821 * CVE-2026-48978 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ##Description: This update for helm fixes the following issues * Update to version 3.21.2. * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2823=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2823=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2823=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2823=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2823=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2823=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2823=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2823=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2823=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2823=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2823=1 * SUSE Linux Enterprise Server for SAP Applications 15SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2823=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2823=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * Containers Module 15-SP7 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5(aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.21.2-150000.1.80.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html *https://www.suse.com/security/cve/CVE-2026-48978.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 * https://bugzilla.suse.com/show_bug.cgi?id=1270127 . Update for helm fixes two vulnerabilities including one affecting credential management and privilege escalation.. SUSE helm patch, credential management, security update SUSE, privilege escalation, vulnerability fix. . Severity: Important. LinuxSecurity.com Team
Update to 4.2.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5b642da12e 2026-07-08 00:57:00.088478+00:00 -------------------------------------------------------------------------------- Name : helm Product : Fedora 44 Version : 4.2.2 Release : 1.fc44 URL : https://github.com/helm/helm Summary : The Kubernetes Package Manager Description : Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Use Helm to: - Find and use popular software packaged as Helm Charts to run in Kubernetes - Share your own applications as Helm Charts - Create reproducible builds of your Kubernetes applications - Intelligently manage your Kubernetes manifest files - Manage releases of Helm packages. -------------------------------------------------------------------------------- Update Information: Update to 4.2.2 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 29 2026 Mikel Olasagasti Uranga - 4.2.2-1 - Update to 4.2.2 - Closes rhbz#2488246 * Thu May 14 2026 Mikel Olasagasti Uranga - 4.2.0-1 - Update to 4.2.0 - Closes rhbz#2446841 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457445 - CVE-2026-35204 helm: Helm: Arbitrary file write via specially crafted plugin [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457445 [ 2 ] Bug #2457446 - CVE-2026-35205 helm: Helm: Arbitrary code execution due to insufficient plugin provenance verification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457446 [ 3 ] Bug #2486237 - CVE-2026-45287 helm: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486237 -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5b642da12e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # helm-4.2.2-2.1 on GA media Announcement ID: openSUSE-SU-2026:11186-1 Rating: moderate Cross-References: * CVE-2026-48978 CVSS scores: * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the helm-4.2.2-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * helm 4.2.2-2.1 * helm-bash-completion 4.2.2-2.1 * helm-fish-completion 4.2.2-2.1 * helm-zsh-completion 4.2.2-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48978.html . An important openSUSE advisory addressing a moderate risk vulnerability in helm, requiring updates for system integrity.. openSUSE, helm, security update, moderate risk, patch. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for helm Announcement ID: SUSE-SU-2026:22455-1 Release Date: 2026-06-30T11:41:55Z Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: * update to 3.21.2: * chore(deps): bump the k8s-io group with 2 updates 1259634 (dependabot[bot]) * fixes b52e276 (Matheus Pimenta) * chore(deps): bump the k8s-io group across 1 directory with 2 updates 3342dbf (dependabot[bot]) * Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 * chore(deps): bump github.com/distribution/distribution/v3 * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 * chore(deps): bump github.com/Masterminds/semver/v3from 3.4.0 to 3.5.0 * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 * update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-603=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-slfo.1.1_1.1 * helm-3.21.2-slfo.1.1_1.1 * SUSE Linux Micro 6.1 (noarch) * helm-bash-completion-3.21.2-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 . Important security update available for helm in SUSE Linux Micro addressing a validation bypass issue. Install urgently.. SUSE security update, helm patch, privilege escalation, Linux Micro, important security fix. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for helm Announcement ID: SUSE-SU-2026:22432-1 Release Date: 2026-06-29T10:32:23Z Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: * update to 3.21.2: * chore(deps): bump the k8s-io group with 2 updates 1259634 (dependabot[bot]) * fixes b52e276 (Matheus Pimenta) * chore(deps): bump the k8s-io group across 1 directory with 2 updates 3342dbf (dependabot[bot]) * Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 * chore(deps): bump github.com/distribution/distribution/v3 * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 * chore(deps): bump github.com/Masterminds/semver/v3from 3.4.0 to 3.5.0 * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 * update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-773=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * helm-debuginfo-3.21.2-1.1 * helm-3.21.2-1.1 * SUSE Linux Micro 6.0 (noarch) * helm-bash-completion-3.21.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 . SUSE releases important security update for helm addressing CVE-2026-39821 vulnerability with installation guidance.. SUSE, helm, security patch, privilege escalation, important update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for helm Announcement ID: SUSE-SU-2026:22305-1 Release Date: 2026-06-21T00:44:54Z Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: * Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 * chore(deps): bump github.com/distribution/distribution/v3 * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 * chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 *chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1006=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1006=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * helm-zsh-completion-3.21.1-160000.1.2 * helm-fish-completion-3.21.1-160000.1.1 * helm-zsh-completion-3.21.1-160000.1.1 * helm-bash-completion-3.21.1-160000.1.1 * helm-fish-completion-3.21.1-160000.1.2 * helm-bash-completion-3.21.1-160000.1.2 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * helm-3.21.1-160000.1.1 * helm-debuginfo-3.21.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (s390x) * helm-debuginfo-3.21.1-160000.1.2 * helm-3.21.1-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * helm-3.21.1-160000.1.1 * helm-debuginfo-3.21.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * helm-fish-completion-3.21.1-160000.1.1 * helm-zsh-completion-3.21.1-160000.1.1 * helm-bash-completion-3.21.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 . Critical security update for SUSE helm addresses privilege escalation risk with important solutions and patch instructions.. SUSE helm security update, privilege escalation patch, SUSE vulnerability remediation. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for helm ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20994-1 Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for helm fixes the following issue - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: - Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates - chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 - chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 - chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 - chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 - chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 - chore(deps): bump github.com/distribution/distribution/v3 - chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 - chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 - chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 - chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 - chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 - chore(deps): bumpgolang.org/x/text from 0.35.0 to 0.37.0 Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1006=1 Package List: - openSUSE Leap 16.0: helm-3.21.1-160000.1.1 helm-bash-completion-3.21.1-160000.1.2 helm-fish-completion-3.21.1-160000.1.2 helm-zsh-completion-3.21.1-160000.1.2 References: * https://www.suse.com/security/cve/CVE-2026-39821.html . This update addresses a privilege escalation issue in helm on openSUSE with important fixes for better security.. openSUSE helm security update privilege escalation bug. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.