{
  "threat_severity" : "Moderate",
  "public_date" : "2026-04-09T21:02:13Z",
  "bugzilla" : {
    "description" : "github.com/helm/helm: Helm: Files written to unexpected directory via specially crafted Chart",
    "id" : "2457151",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2457151"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-22",
  "details" : [ "Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar  [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as given by the --destination and --untardir flags), rather than the expected output directory suffixed by the chart's name. This vulnerability is fixed in 3.20.2 and 4.1.4.", "A flaw was found in Helm, a package manager for Kubernetes. A remote attacker could exploit this vulnerability by providing a specially crafted Chart to the `helm pull --untar` command. This would cause the Chart's contents to be written to an unintended directory, potentially overwriting existing files or placing malicious files in an accessible location, leading to data integrity and availability issues." ],
  "affected_release" : [ {
    "product_name" : "Helm CLI 4.1",
    "release_date" : "2026-06-16T00:00:00Z",
    "advisory" : "RHSA-2026:26441",
    "cpe" : "cpe:/a:redhat:helm_cli:4.1::el9",
    "package" : "helm-cli-4.1.4"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.8",
    "release_date" : "2026-06-28T00:00:00Z",
    "advisory" : "RHSA-2026:30650",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.8::el9",
    "package" : "multicluster-engine/backplane-rhel9-operator:1782476869"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.13",
    "release_date" : "2026-06-28T00:00:00Z",
    "advisory" : "RHSA-2026:30651",
    "cpe" : "cpe:/a:redhat:acm:2.13::el9",
    "package" : "rhacm2/multicloud-integrations-rhel9:1782256081"
  } ],
  "package_state" : [ {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/addon-manager-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/hypershift-addon-rhel9-operator",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/managedcluster-import-controller-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/multicloud-manager-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/placement-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/registration-operator-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/registration-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/work-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/acm-governance-policy-addon-controller-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Affected",
    "package_name" : "rhacm2/multiclusterhub-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4",
    "fix_state" : "Not affected",
    "package_name" : "rhacs-eng/release-main",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4",
    "fix_state" : "Not affected",
    "package_name" : "rhacs-eng/release-operator",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4",
    "fix_state" : "Not affected",
    "package_name" : "rhacs-eng/release-roxctl",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4",
    "fix_state" : "Not affected",
    "package_name" : "rhacs-eng/release-scanner-v4",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-35206\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-35206\nhttps://github.com/helm/helm/commit/4e7994d4467182f535b6797c94b5b0e994a91436\nhttps://github.com/helm/helm/releases/tag/v4.1.4\nhttps://github.com/helm/helm/security/advisories/GHSA-hr2v-4r36-88hr" ],
  "name" : "CVE-2026-35206",
  "csaw" : false
}