Back Linuxsecurity SUSE Helm Important DoS Credential Exfiltration Vuln 2026-23506
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
## This update for helm fixes the following issues: Update to version 3.21.1: * CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method- Override header and bypass established access control (bsc#1277949). * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276644). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). * CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).
## This update for helm fixes the following issues: Update to version 3.21.1: * CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method- Override header and bypass established access control (bsc#1277949). * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276644). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). * CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).
* CVE-2026-37236 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-37236 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-37236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-48978 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Announcement ID: SUSE-SU-2026:23506-1 Release Date: 2026-09-08T14:27:43Z Rating: important
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
