Junglewise Threat Intelligence

CVE-2026-35205: Helm signature verification bypass for plugins missing provenance files

CVE-2026-35205 · Severity: high · CVSS 7.8 · Published 2026-04-09

Technologies: Helm, helm.sh/helm/v4 (Go). Vendors: Helm, Go.

Executive brief

Helm, a popular package manager for Kubernetes, contains a security flaw where it fails to properly verify the digital signatures of plugins. If a user is tricked into installing a malicious plugin that is missing its security verification file, Helm will proceed with the installation even when signature verification is required. This could allow an attacker to execute unauthorized code on the user's system through plugin hooks.

Technical details

A 'fail-open' vulnerability exists in Helm's plugin installer (internal/plugin/installer/installer.go) for versions 4.0.0 through 4.1.3. When signature verification is explicitly required during a plugin installation or update, Helm fails to error out if the provenance (.prov) file is entirely absent. An attacker can exploit this by providing a malicious plugin archive without a provenance file, bypassing the cryptographic integrity checks. If a user installs such a plugin, malicious plugin hooks can execute arbitrary code with the privileges of the Helm process. The issue is resolved in version 4.1.4 by ensuring the installer returns an error when provenance data is missing during a verified install.

Affected products

  • Helm Helm >= 4.0.0, < 4.1.4

Timeline

  • 2026-04-09: disclosed
  • 2026-04-09: patched: Fixed in version 4.1.4
  • 2026-04-09: advisory

References

Related threats