CVE-2025-32386

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/04/2025
Last modified:
03/09/2025

Description

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved in Helm v3.17.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* 3.17.3 (excluding)