Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.56% | — | MailuAIMailu Helm-chartsAI | 21/9/2026 | 24/9/2026 | Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header… | |
| Aplazada | Media (5.3) | 0.46% | — | Flux Source ControllerAIKubernetesAIFlux Kustomize ControllerAIFlux Helm ControllerAI | 8/9/2026 | 30/9/2026 | The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to influence the contents of a bucket referenced by a `Bucket` resource can cause… | |
| Pendiente de análisis | Alta (8.4) | 1.0% | — | RenovateAIHelmAI | 19/8/2026 | 8/9/2026 | Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization. Attackers with repository write access can craft malicious Chart.yaml files to execute arbitrary commands… | |
| Pendiente de análisis | Alta (8.4) | 1.0% | — | RenovateAIKubernetes KustomizeAIHelmAI | 19/8/2026 | 8/9/2026 | Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious kustomization.yaml files with specially… | |
| Pendiente de análisis | Alta (8.4) | 0.69% | — | RenovateAIHelmAI | 19/8/2026 | 1/10/2026 | Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed… | |
| Pendiente de análisis | Alta (7.4) | 0.47% | — | Openshift ConsoleAIOpenshift HelmAI | 11/8/2026 | 21/9/2026 | A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and… | |
| Analizada | Media (5.3) | 0.49% | — | Helm | 17/7/2026 | 30/7/2026 | Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause… | |
| Pendiente de análisis | Alta (8.6) | 0.46% | — | Argo CD Helm ChartAIArgo Repo-serverAI | 13/7/2026 | 15/7/2026 | Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution. | |
| Analizada | Alta (8.1) | 0.41% | — | Openfga Helm ChartsOpenfga | 9/7/2026 | 14/7/2026 | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same… | |
| Analizada | Baja (2.1) | 0.34% | — | Openfga Helm ChartsOpenfga | 9/7/2026 | 14/7/2026 | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns can compare case-distinct values such as user:Alice and… | |
| Pendiente de análisis | Media (5.3) | 0.31% | — | Bitnami Mariadb GaleraAIBitnami Mariadb Galera Helm ChartAI | 18/6/2026 | 22/6/2026 | Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-check user. The MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWORD environment variables defaulted to monitor and monitor respectively. This user is granted… | |
| Analizada | Media (5.3) | 0.13% | — | Openfga Helm ChartsOpenfga | 10/6/2026 | 17/6/2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0. | |
| Aplazada | Crítica (10) | 0.44% | — | Cloudpirates Open Source Helm ChartsAIGithub ActionsAI | 1/6/2026 | 22/7/2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been… | |
| Aplazada | Crítica (10) | 0.44% | — | Cloudpirates Open Source Helm ChartsAIGithub ActionsAI | 1/6/2026 | 22/7/2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens without requiring… | |
| Aplazada | Alta (7.2) | 0.32% | — | Martin Helmich HbookAI | 27/5/2026 | 17/6/2026 | The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Pendiente de análisis | Crítica (9.9) | 0.44% | — | Fleet Helm DeployerAI | 13/5/2026 | 17/6/2026 | Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`. | |
| Analizada | Media (5) | 0.23% | — | Openfga Helm ChartsOpenfga | 22/4/2026 | 17/6/2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result for a subsequent… | |
| Analizada | Media (4.8) | 0.19% | — | Helm | 9/4/2026 | 17/6/2026 | Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as given by the… | |
| Modificada | Alta (8.4) | 0.28% | — | Helm | 9/4/2026 | 15/7/2026 | Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4. | |
| Modificada | Alta (8.4) | 0.19% | — | Helm | 9/4/2026 | 15/7/2026 | Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not include a version:… | |
| Analizada | Alta (8.8) | 0.27% | — | Openfga Helm ChartsOpenfga | 6/4/2026 | 24/7/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement.… | |
| Aplazada | Crítica (9.2) | 0.29% | — | Element Server Suite Community EditionAIMatrix-toolsAIElement ESS Community Helm ChartAI | 12/2/2026 | 17/6/2026 | Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network… | |
| Analizada | Media (5.8) | 0.33% | — | Openfga Helm ChartsOpenfga | 6/2/2026 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2.51, v.1.8.5 <= docker <= v.1.11.2) are vulnerable to improper policy enforcement when certain Check calls are executed.… | |
| Aplazada | Alta (8.5) | 0.28% | — | Minder GOAIHelmAI | 21/11/2025 | 17/6/2026 | Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to. This issue has… | |
| Analizada | Media (5.8) | 0.29% | — | Openfga Helm ChartsOpenfga | 21/11/2025 | 17/6/2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject… |