Skip to content
openSUSE Helm Important Buffers And Authorization Exploits 2026-21809

openSUSE Helm Important Buffers And Authorization Exploits 2026-21809

Linuxsecurity LinuxSecurity Advisories September 10, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

This update for helm fixes the following issues:

Update to version 3.21.1:

- CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST

request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277949).

- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS

via oversized inputs (bsc#1276644).

- CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to

exfiltrate credentials and refresh tokens (bsc#1270127).

- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).

- CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic

- CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization

- openSUSE Leap 16.0:

helm-3.21.3-160000.2.1

helm-bash-completion-3.21.3-160000.2.1

helm-fish-completion-3.21.3-160000.2.1

helm-zsh-completion-3.21.3-160000.2.1

*

*

*

*

*

*

*

*

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases