Skip to content
openSUSE helm Low Credential Exfiltration Issue CVE-2026-48978 2026-21331

openSUSE helm Low Credential Exfiltration Issue CVE-2026-48978 2026-21331

Linuxsecurity LinuxSecurity Advisories July 15, 2026

- CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to

exfiltrate credentials and refresh tokens (bsc#1270127).

- Update to version 3.21.2.

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

zypper in -t patch openSUSE-Leap-16.0-1235=1

- openSUSE Leap 16.0:

helm-3.21.2-160000.2.1

helm-bash-completion-3.21.2-160000.2.1

helm-fish-completion-3.21.2-160000.2.1

helm-zsh-completion-3.21.2-160000.2.1

*

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities