logo

CVE-2025-55199 helm.sh/helm/v3

Package

Manager: go
Name: helm.sh/helm/v3
Vulnerable Version: >=0 <3.18.5

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00012 pctl0.01219

Details

Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion A Helm contributor discovered that it was possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. ### Impact A malicious chart can point `$ref` in _values.schema.json_ to a device (e.g. `/dev/*`) or other problem file which could cause Helm to use all available memory and have an out of memory (OOM) termination. ### Patches This issue has been resolved in Helm v3.18.5. ### Workarounds Make sure that all Helm charts that are being loaded into Helm doesn't have any reference of `$ref` pointing to `/dev/zero`. ### References Helm's security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document. ### Credits Disclosed by Jakub Ciolek at AlphaSense.

Metadata

Created: 2025-08-14T00:01:34Z
Modified: 2025-08-14T17:14:53Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-9h84-qmv7-982p/GHSA-9h84-qmv7-982p.json
CWE IDs: ["CWE-770"]
Alternative ID: GHSA-9h84-qmv7-982p
Finding: F067
Auto approve: 1