## Vulnerability Report exsctl v0.229.0 bundles helm.sh/helm/v3 v3.20.2 which transitively introduces oras.land/oras-go/v2 v2.6.0 — four published CVEs: - CVE-2026-50151 HIGH Bearer token leaked via cross-host redirect - CVE-2026-50163 HIGH Hardlink path traversal exposing credentials - CVE-2026-48978 MEDIUM SSRF via WWW-Authenticate Bearer realm - CVE-2026-50162 MEDIUM Symlink traversal write outside workingDir Fix: bump helm to v3.21.3 (uses oras-go v2.6.1).
Vulnerability Report
exsctl v0.229.0 bundles helm.sh/helm/v3 v3.20.2 which transitively introduces oras.land/oras-go/v2 v2.6.0 — four published CVEs:
Fix: bump helm to v3.21.3 (uses oras-go v2.6.1).