{"schema_version":"1.7.5","id":"SUSE-SU-2026:22455-1","published":"2026-06-30T11:14:22Z","modified":"2026-07-04T18:24:20.273620558Z","related":["CVE-2026-39821"],"upstream":["CVE-2026-39821"],"summary":"Security update for helm","details":"This update for helm fixes the following issue\n\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266598).\n\nChanges for helm:\n\n- update to 3.21.2:\n * chore(deps): bump the k8s-io group with 2 updates 1259634\n (dependabot[bot])\n * fixes b52e276 (Matheus Pimenta)\n * chore(deps): bump the k8s-io group across 1 directory with 2\n updates 3342dbf (dependabot[bot])\n- Update to version 3.21.1:\n * Fixed nil pointer panic that could happen with helm template in\n ClientOnly flows. Now correctly returns a template error #31920\n * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026\n #32152\n * Bumped Go from 1.25 to 1.26 #32168\n * Dependency version updates\n - chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1\n - chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0\n - chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0\n - chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0\n - chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3\n - chore(deps): bump github.com/distribution/distribution/v3\n - chore(deps): bump github.com/containerd/containerd from\n 1.7.30 to 1.7.32\n - chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0\n to 3.5.0\n - chore(deps): bump github.com/mattn/go-shellwords from 1.0.12\n to 1.0.13\n - chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0\n - chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0\n - chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0\n- update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821)\n","affected":[{"package":{"name":"helm","ecosystem":"SUSE:Linux Micro 6.1","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Micro%206.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.21.2-slfo.1.1_1.1"}]}],"ecosystem_specific":{"binaries":[{"helm":"3.21.2-slfo.1.1_1.1","helm-bash-completion":"3.21.2-slfo.1.1_1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22455-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622455-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266598"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"}]}