Research / Finding
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment F-HELM-UNTAR-ROOT-COLLAPSE-001
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
4.8medium
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Fixed in: 3.20.2, 4.1.4
patched
details
Finding IDs F-HELM-UNTAR-ROOT-COLLAPSE-001 CVE CVE-2026-35206 GHSA GHSA-hr2v-4r36-88hr Status patched Fixed in 3.20.2, 4.1.4 Recorded credit Oleh Konko (@1seal) Note GHSA-hr2v-4r36-88hr CVSS vector CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVE registry state PUBLISHED CVE state checked 23 Sep 2026 Upstream title Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment Upstream publication 9 Apr 2026 Upstream updated 9 Apr 2026 Metadata fetched 23 Sep 2026 Upstream @1seal credit @1seal: reporter (accepted) F-HELM-UNTAR-ROOT-COLLAPSE-001: File / path escapes. Archive root handling defeats extraction containment. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-HELM-UNTAR-ROOT-COLLAPSE-001
Security area (1seal assessment): Authorization. Archive root handling defeats extraction containment. Reviewed 24 Sep 2026.
—score not recorded
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment
released
details
Finding IDs F-HELM-UNTAR-ROOT-COLLAPSE-001 Status released Recorded credit v4.1.4 release note thanks @1seal among the reporters. Note GHSA-hr2v-4r36-88hr / CVE-2026-35206 published; fixed in Helm v4.1.4. changelog lists commit 4e7994d44671 for the chart dot-name path bug. F-HELM-UNTAR-ROOT-COLLAPSE-001: File / path escapes. Archive root handling defeats extraction containment. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-HELM-UNTAR-ROOT-COLLAPSE-001
Security area (1seal assessment): Authorization. Archive root handling defeats extraction containment. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .