3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether helm.sh/helm/v4 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.6
CVE-2026-35204
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
HIGH 7.8
CVE-2026-35205
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
UNKNOWN
CVE-2026-35206
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes