Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved in Helm v3.17.3.
History

Thu, 10 Apr 2025 14:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 10 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 22:45:00 +0000

Type Values Removed Values Added
Description Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved in Helm v3.17.3.
Title Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Weaknesses CWE-770
CWE-789
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-10T13:39:53.113Z

Reserved: 2025-04-06T19:46:02.462Z

Link: CVE-2025-32386

cve-icon Vulnrichment

Updated: 2025-04-10T13:39:48.336Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-09T23:15:37.750

Modified: 2025-04-11T15:40:10.277

Link: CVE-2025-32386

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-04-09T22:28:44Z

Links: CVE-2025-32386 - Bugzilla