CVE-2025-55198
- EPSS 0.02%
- Veröffentlicht 13.08.2025 23:23:56
- Zuletzt bearbeitet 21.08.2025 21:28:21
Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves e...
CVE-2025-55199
- EPSS 0.01%
- Veröffentlicht 13.08.2025 23:23:43
- Zuletzt bearbeitet 21.08.2025 21:25:20
Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been r...
CVE-2025-53547
- EPSS 0.01%
- Veröffentlicht 08.07.2025 21:39:59
- Zuletzt bearbeitet 03.09.2025 16:26:24
Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that ...
CVE-2025-32386
- EPSS 0.07%
- Veröffentlicht 09.04.2025 22:28:44
- Zuletzt bearbeitet 03.09.2025 17:03:12
Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhaust...
CVE-2025-32387
- EPSS 0.03%
- Veröffentlicht 09.04.2025 22:28:33
- Zuletzt bearbeitet 03.09.2025 17:03:46
Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. This issue ...
CVE-2019-25210
- EPSS 0.22%
- Veröffentlicht 03.03.2024 21:15:49
- Zuletzt bearbeitet 11.02.2025 15:58:14
An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the ...
CVE-2024-26147
- EPSS 0.22%
- Veröffentlicht 21.02.2024 23:15:08
- Zuletzt bearbeitet 09.01.2025 14:40:25
Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin...
CVE-2024-25620
- EPSS 0.17%
- Veröffentlicht 15.02.2024 00:15:45
- Zuletzt bearbeitet 09.01.2025 13:55:40
Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file includes a relative path change, the chart would be sav...
CVE-2023-25165
- EPSS 0.19%
- Veröffentlicht 08.02.2023 20:15:24
- Zuletzt bearbeitet 21.11.2024 07:49:14
Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for that hostname. To get the IP add...
CVE-2022-23526
- EPSS 0.06%
- Veröffentlicht 15.12.2022 19:15:17
- Zuletzt bearbeitet 21.11.2024 06:48:45
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that can cause a segmentation violation. The _chartutil_ package contains a parser tha...