CVE Vulnerabilities

CVE-2026-35205

Not Failing Securely ('Failing Open')

Published: Apr 09, 2026 | Modified: Jun 30, 2026
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.

Weakness

When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Affected Software

NameVendorStart VersionEnd Version
HelmHelm4.0.0 (including)4.1.4 (excluding)
Helm CLI 4.1RedHathelm-cli-4.1.4*

Potential Mitigations

References