{"id":"SUSE-SU-2026:23688-1","summary":"Security update for helm","details":"This update for helm fixes the following issues:\n\nUpdate to version 3.21.1:\n\n- CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST\n  request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277949).\n- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS\n  via oversized inputs (bsc#1276644).\n- CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to\n  exfiltrate credentials and refresh tokens (bsc#1270127).\n- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).\n- CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic\n  (bsc#1272402).\n- CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization\n  policies via mixed-case or canonical-case header matches (bsc#1278270).\n- CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273).\n- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS\n  servers (bsc#1278688).\n- gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation\n  (bsc#1276514).\n","modified":"2026-09-29T18:23:12.089974044Z","published":"2026-09-08T14:29:35Z","related":["CVE-2026-37236","CVE-2026-41178","CVE-2026-48978","CVE-2026-50151","CVE-2026-63308","CVE-2026-84303","CVE-2026-84304","CVE-2026-84445"],"upstream":["CVE-2026-37236","CVE-2026-41178","CVE-2026-48978","CVE-2026-50151","CVE-2026-63308","CVE-2026-84303","CVE-2026-84304","CVE-2026-84445"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623688-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270127"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271660"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272402"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276644"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277949"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278270"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278273"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278688"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-37236"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50151"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84304"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84445"}],"affected":[{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.21.3-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"helm-fish-completion":"3.21.3-160000.2.1","helm-zsh-completion":"3.21.3-160000.2.1","helm":"3.21.3-160000.2.1","helm-bash-completion":"3.21.3-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23688-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.21.3-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"helm":"3.21.3-160000.2.1","helm-bash-completion":"3.21.3-160000.2.1","helm-fish-completion":"3.21.3-160000.2.1","helm-zsh-completion":"3.21.3-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23688-1.json"}}],"schema_version":"1.9.0"}