Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-35204High· 8.6PoCHelm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
CVE-2026-35205High· 7.8Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
CVE-2026-35206MediumHelm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
CVE-2025-32387Medium· 6.5Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
CVE-2025-32386Medium· 6.5Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
CVE-2022-36055Medium· 6.5Helm Vulnerable to denial of service through string value parsing
CVE-2020-4053Low· 3.7Plugin archive directory traversal in Helm
CVE-2021-21303Medium· 6.5Improper Neutralization of Special Elements in Output in helm.sh/helm/v3
CVE-2021-32690MediumHelm passes repository credentials to alternate domain
CVE-2020-15186Low· 3.4Improper Sanitizing of plugin names in helm
CVE-2020-15185Low· 2.2Repository index file allows for duplicates of the same chart entry in helm
CVE-2020-15187Low· 3.0plugin.yaml file allows for duplicate entries in helm
CVE-2020-15184Low· 3.7Aliases are never checked in helm
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.