SUSE Helm Vulnerabilities Lead to DoS and Credential Exfiltration Risks

SUSE Helm Vulnerabilities Lead to DoS and Credential Exfiltration Risks

First seen 10 Sep 2026, 15:20 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Recent updates for SUSE Linux Micro 6.0 and mcphost address multiple vulnerabilities, including CVE-2026-41178, which allows denial-of-service (DoS) attacks through oversized inputs in baggage parsing. Additionally, CVE-2026-48978 enables malicious registries to exfiltrate credentials via hijacked Bearer tokens. The updates affect systems using helm and mcphost, with CVE-2026-37236 allowing HTTP method overrides that can bypass access controls. The vulnerabilities were disclosed between June and September 2026, with patches released on September 6 and 8. Administrators are urged to apply the updates immediately to mitigate risks. The vulnerabilities have varying CVSS scores, indicating differing levels of severity. Current status shows that CVE-2026-41178 and CVE-2026-48978 are particularly concerning due to their potential impact on system integrity and security.

Key Points: • CVE-2026-41178 allows DoS via oversized inputs in baggage parsing. • CVE-2026-48978 enables credential exfiltration through malicious registries. • Immediate patching is recommended for affected SUSE systems.

Ask AI about this cluster

Timeline

2026-06-04
CVE-2026-41178 published
Vulnerability disclosed that allows DoS via oversized inputs in baggage parsing.
Linuxsecurity
2026-07-17
CVE-2026-48978 published
Vulnerability disclosed that allows credential exfiltration through hijacked Bearer tokens.
Linuxsecurity
2026-07-17
CVE-2026-50151 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-27
CVE-2026-81092 published
Vulnerability disclosed that allows resource exposure due to lack of Host header checks.
Linuxsecurity
2026-08-28
CVE-2026-37236 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
CVE-2026-33630 published
Vulnerability disclosed affecting helm with a CVSS score of 8.7.
Linuxsecurity
2026-09-06
Patch released for mcphost
SUSE released an update addressing CVE-2026-41178 and CVE-2026-81092.
Linuxsecurity
2026-09-08
Patch released for helm
SUSE released an update addressing CVE-2026-37236, CVE-2026-48978, and CVE-2026-50151.
Linuxsecurity
2026-09-10
Current status
Administrators are urged to apply patches to mitigate risks from multiple vulnerabilities.
Linuxsecurity