helm.sh/helm/v3
Activity
- Latest release
- 4d ago
- Total releases
- 67
- Cadence
- ~28 days
- Last 12 months
- 17
Details
- First release
- Nov 01, 2019
| Version | Released | |
|---|---|---|
v3.22.0
minor
|
v3.22.0
minor
Dependencies (43)
+ 35 more |
|
v3.22.0-rc.1
pre
|
v3.22.0-rc.1
pre
Dependencies (43)
+ 35 more |
|
v3.21.4
patch
|
v3.21.4
patch
Dependencies (44)
+ 36 more |
|
v3.21.3
patch
|
v3.21.3
patch
Dependencies (43)
+ 35 more |
|
v3.21.2
patch
|
v3.21.2
patch
Dependencies (44)
+ 36 more |
|
v3.21.1
patch
|
v3.21.1
patch
Dependencies (44)
+ 36 more |
|
v3.21.0-rc.1
pre
|
v3.21.0-rc.1
pre
Dependencies (44)
+ 36 more |
|
v3.21.0
minor
|
v3.21.0
minor
Dependencies (44)
+ 36 more |
|
v3.20.2
patch
|
v3.20.2
patch
Dependencies (44)
+ 36 more |
|
v3.20.1
patch
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.20.1
patch
Dependencies (44)
+ 36 more |
|
v3.19.5
patch
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.19.5
patch
Dependencies (44)
+ 36 more |
|
v3.20.0-rc.1
pre
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.20.0-rc.1
pre
Dependencies (44)
+ 36 more |
|
v3.20.0
minor
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.20.0
minor
Dependencies (44)
+ 36 more |
|
v3.19.4
patch
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.19.4
patch
Dependencies (44)
+ 36 more |
|
v3.19.3
patch
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.19.3
patch
Dependencies (44)
+ 36 more |
|
v3.19.2
patch
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.19.2
patch
Dependencies (44)
+ 36 more |
|
v3.19.1
patch
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.19.1
patch
Dependencies (44)
+ 36 more |
|
v3.19.0
minor
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.19.0
minor
Dependencies (44)
+ 36 more |
|
v3.19.0-rc.1
pre
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.19.0-rc.1
pre
Dependencies (44)
+ 36 more |
|
v3.18.6
patch
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.18.6
patch
Dependencies (44)
+ 36 more |
|
v3.18.5
patch
1 CVE
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev |
v3.18.5
patch
Dependencies (44)
+ 36 more |
|
v3.18.4
patch
3 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.18.4
patch
Dependencies (44)
+ 36 more |
|
v3.18.3
patch
4 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.18.3
patch
Dependencies (44)
+ 36 more |
|
v3.18.1
minor
4 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.18.1
minor
Dependencies (44)
+ 36 more |
|
v3.17.3
patch
4 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.17.3
patch
Dependencies (44)
+ 36 more |
|
v3.17.2
patch
6 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.17.2
patch
Dependencies (44)
+ 36 more |
|
v3.17.0
minor
6 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.17.0
minor
Dependencies (44)
+ 36 more |
|
v3.16.3
patch
6 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.16.3
patch
Dependencies (43)
+ 35 more |
|
v3.16.1
minor
6 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.16.1
minor
Dependencies (43)
+ 35 more |
|
v3.15.4
patch
6 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.15.4
patch
Dependencies (43)
+ 35 more |
|
v3.15.3
patch
6 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.15.3
patch
Dependencies (43)
+ 35 more |
|
v3.15.2
patch
6 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.15.2
patch
Dependencies (43)
+ 35 more |
|
v3.15.0
minor
6 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.15.0
minor
Dependencies (43)
+ 35 more |
|
v3.14.2
patch
6 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.14.2
patch
Dependencies (43)
+ 35 more |
|
v3.14.1
patch
7 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.14.1
patch
Dependencies (43)
+ 35 more |
|
v3.14.0
minor
8 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.14.0
minor
Dependencies (43)
+ 35 more |
|
v3.13.3
minor
8 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.13.3
minor
Dependencies (43)
+ 35 more |
|
v3.12.2
patch
8 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.12.2
patch
Dependencies (43)
+ 35 more |
|
v3.12.1
minor
8 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.12.1
minor
Dependencies (43)
+ 35 more |
|
v3.11.0
minor
9 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.11.0
minor
Dependencies (41)
+ 33 more |
|
v3.11.0-rc.1
pre
9 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.11.0-rc.1
pre
Dependencies (41)
+ 33 more |
|
v3.10.3
minor
9 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.10.3
minor
Dependencies (43)
+ 35 more |
|
v3.10.0-rc.1
pre
12 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23525
GO-2022-1165
BIT-helm-2022-23525
GHSA-53c4-hhmh-vw5q
Dec 22, 2022
Denial of service via repository index file in helm.sh/helm/v3 Applications that use the repo package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The repo package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The repo package parses the index file of the repository and loads it into memory. Some index files can cause array data structures to be created causing a memory violation. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23526
GO-2022-1166
BIT-helm-2022-23526
GHSA-67fx-wx78-jx33
Dec 22, 2022
Denial of service via schema file in helm.sh/helm/v3 Certain JSON schema validation files can cause a Helm Client to panic, leading to a possible denial of service. The chartutil package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The chartutil package parses the schema file and loads it into memory, but some schema files can cause array data structures to be created causing a memory violation. The Helm Client will panic with a schema file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23524
GHSA-6rx9-889q-vv2r
BIT-helm-2022-23524
GO-2022-1167
Dec 14, 2022
Helm vulnerable to denial of service through string value parsing
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the strvals package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the strvals package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. ImpactThe strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with input to PatchesThis issue has been resolved in 3.10.3. WorkaroundsSDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the strvals functions. For more informationHelm's security policy is spelled out in detail in our SECURITY document. CreditsDisclosed by Ada Logics in a fuzzing audit sponsored by CNCF. Fixed in
3.10.3
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.10.0-rc.1
pre
Dependencies (41)
+ 33 more |
|
v3.9.4
patch
12 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23525
GO-2022-1165
BIT-helm-2022-23525
GHSA-53c4-hhmh-vw5q
Dec 22, 2022
Denial of service via repository index file in helm.sh/helm/v3 Applications that use the repo package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The repo package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The repo package parses the index file of the repository and loads it into memory. Some index files can cause array data structures to be created causing a memory violation. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23526
GO-2022-1166
BIT-helm-2022-23526
GHSA-67fx-wx78-jx33
Dec 22, 2022
Denial of service via schema file in helm.sh/helm/v3 Certain JSON schema validation files can cause a Helm Client to panic, leading to a possible denial of service. The chartutil package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The chartutil package parses the schema file and loads it into memory, but some schema files can cause array data structures to be created causing a memory violation. The Helm Client will panic with a schema file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23524
GHSA-6rx9-889q-vv2r
BIT-helm-2022-23524
GO-2022-1167
Dec 14, 2022
Helm vulnerable to denial of service through string value parsing
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the strvals package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the strvals package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. ImpactThe strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with input to PatchesThis issue has been resolved in 3.10.3. WorkaroundsSDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the strvals functions. For more informationHelm's security policy is spelled out in detail in our SECURITY document. CreditsDisclosed by Ada Logics in a fuzzing audit sponsored by CNCF. Fixed in
3.10.3
References Updated Sep 10, 2026 · Source: OSV.dev |
v3.9.4
patch
Dependencies (40)
+ 32 more |
|
v3.9.2
patch
13 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23525
GO-2022-1165
BIT-helm-2022-23525
GHSA-53c4-hhmh-vw5q
Dec 22, 2022
Denial of service via repository index file in helm.sh/helm/v3 Applications that use the repo package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The repo package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The repo package parses the index file of the repository and loads it into memory. Some index files can cause array data structures to be created causing a memory violation. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23526
GO-2022-1166
BIT-helm-2022-23526
GHSA-67fx-wx78-jx33
Dec 22, 2022
Denial of service via schema file in helm.sh/helm/v3 Certain JSON schema validation files can cause a Helm Client to panic, leading to a possible denial of service. The chartutil package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The chartutil package parses the schema file and loads it into memory, but some schema files can cause array data structures to be created causing a memory violation. The Helm Client will panic with a schema file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23524
GHSA-6rx9-889q-vv2r
BIT-helm-2022-23524
GO-2022-1167
Dec 14, 2022
Helm vulnerable to denial of service through string value parsing
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the strvals package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the strvals package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. ImpactThe strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with input to PatchesThis issue has been resolved in 3.10.3. WorkaroundsSDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the strvals functions. For more informationHelm's security policy is spelled out in detail in our SECURITY document. CreditsDisclosed by Ada Logics in a fuzzing audit sponsored by CNCF. Fixed in
3.10.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-36055
GO-2022-0962
BIT-helm-2022-36055
GHSA-7hfp-qfw3-5jxh
Sep 02, 2022
Denial of service through string value parsing in helm.sh/helm/v3 Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like --set, --set-string, and others that enable the user to pass in strings that are merged into the values. The strvals package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing an out of memory panic. The Helm Client will panic with input to --set, --set-string, and other value setting flags that causes an out of memory panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.9.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.9.2
patch
Dependencies (40)
+ 32 more |
|
v3.9.0-rc.1
pre
13 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23525
GO-2022-1165
BIT-helm-2022-23525
GHSA-53c4-hhmh-vw5q
Dec 22, 2022
Denial of service via repository index file in helm.sh/helm/v3 Applications that use the repo package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The repo package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The repo package parses the index file of the repository and loads it into memory. Some index files can cause array data structures to be created causing a memory violation. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23526
GO-2022-1166
BIT-helm-2022-23526
GHSA-67fx-wx78-jx33
Dec 22, 2022
Denial of service via schema file in helm.sh/helm/v3 Certain JSON schema validation files can cause a Helm Client to panic, leading to a possible denial of service. The chartutil package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The chartutil package parses the schema file and loads it into memory, but some schema files can cause array data structures to be created causing a memory violation. The Helm Client will panic with a schema file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23524
GHSA-6rx9-889q-vv2r
BIT-helm-2022-23524
GO-2022-1167
Dec 14, 2022
Helm vulnerable to denial of service through string value parsing
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the strvals package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the strvals package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. ImpactThe strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with input to PatchesThis issue has been resolved in 3.10.3. WorkaroundsSDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the strvals functions. For more informationHelm's security policy is spelled out in detail in our SECURITY document. CreditsDisclosed by Ada Logics in a fuzzing audit sponsored by CNCF. Fixed in
3.10.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-36055
GO-2022-0962
BIT-helm-2022-36055
GHSA-7hfp-qfw3-5jxh
Sep 02, 2022
Denial of service through string value parsing in helm.sh/helm/v3 Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like --set, --set-string, and others that enable the user to pass in strings that are merged into the values. The strvals package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing an out of memory panic. The Helm Client will panic with input to --set, --set-string, and other value setting flags that causes an out of memory panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.9.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.9.0-rc.1
pre
Dependencies (40)
+ 32 more |
|
v3.9.0
minor
13 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23525
GO-2022-1165
BIT-helm-2022-23525
GHSA-53c4-hhmh-vw5q
Dec 22, 2022
Denial of service via repository index file in helm.sh/helm/v3 Applications that use the repo package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The repo package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The repo package parses the index file of the repository and loads it into memory. Some index files can cause array data structures to be created causing a memory violation. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23526
GO-2022-1166
BIT-helm-2022-23526
GHSA-67fx-wx78-jx33
Dec 22, 2022
Denial of service via schema file in helm.sh/helm/v3 Certain JSON schema validation files can cause a Helm Client to panic, leading to a possible denial of service. The chartutil package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The chartutil package parses the schema file and loads it into memory, but some schema files can cause array data structures to be created causing a memory violation. The Helm Client will panic with a schema file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23524
GHSA-6rx9-889q-vv2r
BIT-helm-2022-23524
GO-2022-1167
Dec 14, 2022
Helm vulnerable to denial of service through string value parsing
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the strvals package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the strvals package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. ImpactThe strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with input to PatchesThis issue has been resolved in 3.10.3. WorkaroundsSDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the strvals functions. For more informationHelm's security policy is spelled out in detail in our SECURITY document. CreditsDisclosed by Ada Logics in a fuzzing audit sponsored by CNCF. Fixed in
3.10.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-36055
GO-2022-0962
BIT-helm-2022-36055
GHSA-7hfp-qfw3-5jxh
Sep 02, 2022
Denial of service through string value parsing in helm.sh/helm/v3 Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like --set, --set-string, and others that enable the user to pass in strings that are merged into the values. The strvals package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing an out of memory panic. The Helm Client will panic with input to --set, --set-string, and other value setting flags that causes an out of memory panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.9.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.9.0
minor
Dependencies (40)
+ 32 more |
|
v3.8.1
minor
13 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23525
GO-2022-1165
BIT-helm-2022-23525
GHSA-53c4-hhmh-vw5q
Dec 22, 2022
Denial of service via repository index file in helm.sh/helm/v3 Applications that use the repo package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The repo package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The repo package parses the index file of the repository and loads it into memory. Some index files can cause array data structures to be created causing a memory violation. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23526
GO-2022-1166
BIT-helm-2022-23526
GHSA-67fx-wx78-jx33
Dec 22, 2022
Denial of service via schema file in helm.sh/helm/v3 Certain JSON schema validation files can cause a Helm Client to panic, leading to a possible denial of service. The chartutil package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The chartutil package parses the schema file and loads it into memory, but some schema files can cause array data structures to be created causing a memory violation. The Helm Client will panic with a schema file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23524
GHSA-6rx9-889q-vv2r
BIT-helm-2022-23524
GO-2022-1167
Dec 14, 2022
Helm vulnerable to denial of service through string value parsing
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the strvals package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the strvals package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. ImpactThe strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with input to PatchesThis issue has been resolved in 3.10.3. WorkaroundsSDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the strvals functions. For more informationHelm's security policy is spelled out in detail in our SECURITY document. CreditsDisclosed by Ada Logics in a fuzzing audit sponsored by CNCF. Fixed in
3.10.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-36055
GO-2022-0962
BIT-helm-2022-36055
GHSA-7hfp-qfw3-5jxh
Sep 02, 2022
Denial of service through string value parsing in helm.sh/helm/v3 Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like --set, --set-string, and others that enable the user to pass in strings that are merged into the values. The strvals package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing an out of memory panic. The Helm Client will panic with input to --set, --set-string, and other value setting flags that causes an out of memory panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.9.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.8.1
minor
Dependencies (40)
+ 32 more |
|
v3.7.2
patch
13 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23525
GO-2022-1165
BIT-helm-2022-23525
GHSA-53c4-hhmh-vw5q
Dec 22, 2022
Denial of service via repository index file in helm.sh/helm/v3 Applications that use the repo package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The repo package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The repo package parses the index file of the repository and loads it into memory. Some index files can cause array data structures to be created causing a memory violation. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23526
GO-2022-1166
BIT-helm-2022-23526
GHSA-67fx-wx78-jx33
Dec 22, 2022
Denial of service via schema file in helm.sh/helm/v3 Certain JSON schema validation files can cause a Helm Client to panic, leading to a possible denial of service. The chartutil package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The chartutil package parses the schema file and loads it into memory, but some schema files can cause array data structures to be created causing a memory violation. The Helm Client will panic with a schema file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23524
GHSA-6rx9-889q-vv2r
BIT-helm-2022-23524
GO-2022-1167
Dec 14, 2022
Helm vulnerable to denial of service through string value parsing
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the strvals package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the strvals package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. ImpactThe strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with input to PatchesThis issue has been resolved in 3.10.3. WorkaroundsSDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the strvals functions. For more informationHelm's security policy is spelled out in detail in our SECURITY document. CreditsDisclosed by Ada Logics in a fuzzing audit sponsored by CNCF. Fixed in
3.10.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-36055
GO-2022-0962
BIT-helm-2022-36055
GHSA-7hfp-qfw3-5jxh
Sep 02, 2022
Denial of service through string value parsing in helm.sh/helm/v3 Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like --set, --set-string, and others that enable the user to pass in strings that are merged into the values. The strvals package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing an out of memory panic. The Helm Client will panic with input to --set, --set-string, and other value setting flags that causes an out of memory panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.9.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.2
patch
Dependencies (40)
+ 32 more |
|
v3.7.0
minor
13 CVEs
CVE-2026-35206
GO-2026-5435
BIT-helm-2026-35206
GHSA-hr2v-4r36-88hr
Jul 24, 2026
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm Fixed in
3.20.2
References Updated Aug 21, 2026 · Source: OSV.dev
CVE-2025-55198
GO-2025-3888
BIT-helm-2025-55198
GHSA-f9f8-9pmf-xv68
Aug 18, 2025
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Helm May Panic Due To Incorrect YAML Content in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-55199
GO-2025-3887
BIT-helm-2025-55199
GHSA-9h84-qmv7-982p
Aug 18, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm Fixed in
3.18.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-53547
GO-2025-3802
BIT-helm-2025-53547
GHSA-557j-xg8c-q2mm
Jul 21, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm Fixed in
3.18.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32386
GO-2025-3601
BIT-helm-2025-32386
GHSA-4hfp-h4cw-hj8p
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-32387
GO-2025-3602
BIT-helm-2025-32387
GHSA-5xqw-8hwv-wg92
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm Fixed in
3.17.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26147
GO-2024-2575
BIT-helm-2024-26147
GHSA-r53h-jv2g-vpx6
Jun 04, 2024
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3 Fixed in
3.14.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-25620
GO-2024-2554
BIT-helm-2024-25620
GHSA-v53g-5gjp-272r
Feb 29, 2024
Path traversal in helm.sh/helm/v3 Path traversal in helm.sh/helm/v3 Fixed in
3.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25165
GO-2023-1547
BIT-helm-2023-25165
GHSA-pwcw-6f5g-gxf8
Feb 14, 2023
Information disclosure in helm.sh/helm/v3 An information disclosure vulnerability exists in the getHostByName template function. The function getHostByName is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP address the function performs a DNS lookup. The DNS lookup happens when used with "helm install|upgrade|template" or when the Helm SDK is used to render a chart. Information passed into the chart can be disclosed to the DNS servers used to lookup the IP address. For example, a malicious chart could inject getHostByName into a chart in order to disclose values to a malicious DNS server. Fixed in
3.11.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23525
GO-2022-1165
BIT-helm-2022-23525
GHSA-53c4-hhmh-vw5q
Dec 22, 2022
Denial of service via repository index file in helm.sh/helm/v3 Applications that use the repo package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The repo package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The repo package parses the index file of the repository and loads it into memory. Some index files can cause array data structures to be created causing a memory violation. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23526
GO-2022-1166
BIT-helm-2022-23526
GHSA-67fx-wx78-jx33
Dec 22, 2022
Denial of service via schema file in helm.sh/helm/v3 Certain JSON schema validation files can cause a Helm Client to panic, leading to a possible denial of service. The chartutil package contains a parser that loads a JSON Schema validation file. For example, the Helm client when rendering a chart will validate its values with the schema file. The chartutil package parses the schema file and loads it into memory, but some schema files can cause array data structures to be created causing a memory violation. The Helm Client will panic with a schema file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.10.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-23524
GHSA-6rx9-889q-vv2r
BIT-helm-2022-23524
GO-2022-1167
Dec 14, 2022
Helm vulnerable to denial of service through string value parsing
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the strvals package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the strvals package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. ImpactThe strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The Helm Client will panic with input to PatchesThis issue has been resolved in 3.10.3. WorkaroundsSDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the strvals functions. For more informationHelm's security policy is spelled out in detail in our SECURITY document. CreditsDisclosed by Ada Logics in a fuzzing audit sponsored by CNCF. Fixed in
3.10.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-36055
GO-2022-0962
BIT-helm-2022-36055
GHSA-7hfp-qfw3-5jxh
Sep 02, 2022
Denial of service through string value parsing in helm.sh/helm/v3 Applications that use the strvals package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The strvals package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like --set, --set-string, and others that enable the user to pass in strings that are merged into the values. The strvals package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing an out of memory panic. The Helm Client will panic with input to --set, --set-string, and other value setting flags that causes an out of memory panic. Helm is not a long running service so the panic will not affect future uses of the Helm client. Fixed in
3.9.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.0
minor
Dependencies (40)
+ 32 more |