OPENSUSE-SU-2026:21331-1
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 13 Jul 2026, 19:19
Last modified:15 Jul 2026, 10:00
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
13 Jul 2026, 19:19
Published
Vulnerability first disclosed
15 Jul 2026, 10:00
Last Modified
Vulnerability information updated
Description
Security update for helm This update for helm fixes the following issue - CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). Changes for helm: - Update to version 3.21.2.
Affected Systems
- opensuse•helm&distro=openSUSE Leap 16.0
< 3.21.2-160000.2.1