OPENSUSE-SU-2026:21331-1

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 13 Jul 2026, 19:19
Last modified:15 Jul 2026, 10:00

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Jul 2026, 19:19
Published
Vulnerability first disclosed
15 Jul 2026, 10:00
Last Modified
Vulnerability information updated

Description

Security update for helm This update for helm fixes the following issue - CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). Changes for helm: - Update to version 3.21.2.

Affected Systems

  • opensusehelm&distro=openSUSE Leap 16.0

    < 3.21.2-160000.2.1

References (2)