{"schema_version":"1.7.5","id":"SUSE-SU-2026:21461-1","published":"2026-04-30T13:22:50Z","modified":"2026-05-19T06:28:55.295372842Z","related":["CVE-2025-55199","CVE-2026-35206"],"upstream":["CVE-2025-55199","CVE-2026-35206"],"summary":"Security update for helm","details":"This update for helm fixes the following issues:\n\nUpdate to version 3.20.2.\n\nSecurity issued fixed:\n\n- CVE-2025-55199: specially crafted JSON Schema can lead to out of memory (OOM) termination (bsc#1248093).\n- CVE-2026-35206: specially crafted Chart will have contents extracted to immediate output directory rather than to\n  expected output directory suffixed by the Chart's name (bsc#1261938).\n\nOther updates and bugfixes:\n\n- Version 3.20.1:\n  - chore(deps): bump the k8s-io group with 7 updates a2369ca (dependabot[bot])\n  - add image index test 90e1056 (Pedro T�rres)\n  - fix pulling charts from OCI indices 911f2e9 (Pedro T�rres)\n  - Remove refactorring changes from coalesce_test.go 76dad33 (Evans Mungai)\n  - Fix import 45c12f7 (Evans Mungai)\n  - Update pkg/chart/common/util/coalesce_test.go 26c6f19 (Evans Mungai)\n  - Fix lint warning 09f5129 (Evans Mungai)\n  - Preserve nil values in chart already 417deb2 (Evans Mungai)\n  - fix(values): preserve nil values when chart default is empty map 5417bfa (Evans Mungai)\n- Version 3.20.0:\n  - SDK: bump k8s API versions to v0.35.0\n  - v3 backport: Fixed a bug where helm uninstall with --keep-history did not suspend previous deployed releases #12564\n  - v3 backport: Bump Go version to v1.25\n  - bump version to v3.20\n  - chore(deps): bump golang.org/x/text from 0.32.0 to 0.33.0\n  - chore(deps): bump golang.org/x/term from 0.38.0 to 0.39.0\n  - chore(deps): bump github.com/foxcpp/go-mockdns from 1.1.0 to 1.2.0\n  - chore(deps): bump the k8s-io group with 7 updates\n  - [dev-v3] Replace deprecated `NewSimpleClientset`\n  - [dev-v3] Bump Go v1.25, `golangci-lint` v2\n  - chore(deps): bump github.com/BurntSushi/toml from 1.5.0 to 1.6.0\n  - chore(deps): bump github.com/containerd/containerd from 1.7.29 to 1.7.30\n  - fix(rollback): `errors.Is` instead of string comp\n  - fix(uninstall): supersede deployed releases\n  - Use latest patch release of Go in releases\n  - chore(deps): bump golang.org/x/crypto from 0.45.0 to 0.46.0\n  - chore(deps): bump golang.org/x/text from 0.31.0 to 0.32.0\n  - chore(deps): bump golang.org/x/term from 0.37.0 to 0.38.0\n  - chore(deps): bump github.com/spf13/cobra from 1.10.1 to 1.10.2\n  - chore(deps): bump github.com/rubenv/sql-migrate from 1.8.0 to 1.8.1\n  - chore(deps): bump golang.org/x/crypto from 0.44.0 to 0.45.0\n  - chore(deps): bump github.com/cyphar/filepath-securejoin\n  - chore(deps): bump golang.org/x/text from 0.30.0 to 0.31.0\n  - chore(deps): bump golang.org/x/crypto from 0.43.0 to 0.44.0\n  - Remove dev-v3 `helm-latest-version` publish\n  - chore(deps): bump golang.org/x/term from 0.36.0 to 0.37.0 1.7.28 to 1.7.29\n  - Revert \"pkg/registry: Login option for passing TLS config in memory\"\n  - jsonschema: warn and ignore unresolved URN $ref to match v3.18.4\n  - Fix `helm pull` untar dir check with repo urls\n  - chore(deps): bump golang.org/x/crypto from 0.42.0 to 0.43.0\n  - chore(deps): bump github.com/gofrs/flock from 0.12.1 to 0.13.0\n  - chore(deps): bump golang.org/x/text from 0.29.0 to 0.30.0\n  - [backport] fix: get-helm-3 script use helm3-latest-version\n  - pkg/registry: Login option for passing TLS config in memory\n  - Fix deprecation warning\n  - chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.42.0\n  - chore(deps): bump golang.org/x/term from 0.34.0 to 0.35.0\n  - Avoid \"panic: interface conversion: interface {} is nil\"\n  - bump version to v3.19.0\n  - chore(deps): bump github.com/spf13/pflag from 1.0.7 to 1.0.10\n  - fix: set repo authorizer in registry.Client.Resolve()\n  - fix null merge\n  - Add timeout flag to repo add and update flags\n- Version 3.19.5:\n  - Fixed bug where removing subchart value via override resulted in warning #31118\n  - Fixed bug where helm uninstall with --keep-history did not suspend previous deployed releases #12556\n  - fix(rollback): errors.Is instead of string comp 4a19a5b (Hidde Beydals)\n  - fix(uninstall): supersede deployed releases 7a00235 (Hidde Beydals)\n  - fix null merge 578564e (Ben Foster)\n- Version 3.19.4:\n  - Use latest patch release of Go in releases 7cfb6e4 (Matt Farina)\n  - chore(deps): bump github.com/gofrs/flock from 0.12.1 to 0.13.0 59c951f (dependabot[bot])\n  - chore(deps): bump github.com/cyphar/filepath-securejoin d45f3f1\n  - chore(deps): bump golang.org/x/crypto from 0.44.0 to 0.45.0 d459544 (dependabot[bot])\n  - chore(deps): bump golang.org/x/term from 0.36.0 to 0.37.0 becd387 (dependabot[bot])\n  - chore(deps): bump the k8s-io group with 7 updates edb1579\n- Version 3.19.3:\n  - Bump golang.org/x/crypto to v0.45.0\n- Version 3.19.2:\n  - [backport] fix: get-helm-3 script use helm3-latest-version 8766e71 (George Jenkins)\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621461-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248093"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261938"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-55199"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35206"}]}