Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Helm MEDIUM 6.5
CVE-2026-63308

Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go tha…

Fix: after 4.2.3
Fix from $1,600 2026-07-17
Helm HIGH 8.6
CVE-2026-35204

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm…

Fix: 4.1.4+
Fix from $1,950 2026-04-09
Helm HIGH 7.8
CVE-2026-35205

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature ve…

Fix: 4.1.4+
Fix from $1,950 2026-04-09
Helm MEDIUM 6.5
CVE-2025-55199

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could caus…

Fix: 3.18.5+
Fix from $1,600 2025-08-14
Helm MEDIUM 6.5
CVE-2025-55198

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of…

Fix: 3.18.5+
Fix from $1,600 2025-08-14
Helm HIGH 8.6
CVE-2025-53547

Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock fi…

Fix: 3.17.4 / 3.18.4+
Fix from $1,950 2025-07-08
Helm MEDIUM 6.5
CVE-2025-32386

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than com…

Fix: 3.17.3+
Fix from $1,600 2025-04-09
Helm MEDIUM 6.5
CVE-2025-32387

Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leadi…

Fix: 3.17.3+
Fix from $1,600 2025-04-09
Helm MEDIUM 6.5
CVE-2019-25210

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is use…

Mitigation only
Fix from $1,600 2024-03-03
Helm HIGH 7.5
CVE-2024-26147

Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index …

Fix: 3.14.2+
Fix from $1,950 2024-02-21
Helm MEDIUM 6.4
CVE-2024-25620

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a …

Fix: 3.14.1+
Fix from $1,600 2024-02-15
Helm HIGH 7.5
CVE-2022-23525

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the _rep…

Fix: 3.10.3+
Fix from $1,950 2022-12-15
Helm HIGH 7.5
CVE-2022-23526

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_char…

Fix: 3.10.3+
Fix from $1,950 2022-12-15
Helm HIGH 7.5
CVE-2022-23524

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, r…

Fix: 3.10.3+
Fix from $1,950 2022-12-15
Helm HIGH 7.5
CVE-2022-36049

Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allow…

Fix: 0.23.0 / 0.32.0+
Fix from $1,950 2022-09-07
Helm MEDIUM 6.5
CVE-2022-36055

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided by the CNCF, identified input …

Fix: 3.9.4+
Fix from $1,600 2022-09-01
Helm HIGH 8.6
CVE-2021-32690

Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists wher…

Fix: 3.6.1+
Fix from $1,950 2021-06-16
Helm MEDIUM 6.8
CVE-2021-21303

Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-co…

Fix: 3.5.2+
Fix from $1,600 2021-02-05
Helm MEDIUM 6.8
CVE-2020-4053

In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plugins from a tar archive over …

Fix: 3.2.4+
Fix from $1,600 2020-06-16
Helm MEDIUM 5.0
CVE-2020-11013

Their is an information disclosure vulnerability in Helm from version 3.1.0 and before version 3.2.0. `lookup` is a Helm template function introduced…

Fix: 3.2.0+
Fix from $1,600 2020-04-24
Helm CRITICAL 9.8
CVE-2019-18658

In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously desig…

Fix: 2.15.2+
Fix from $2,300 2019-11-12
Helm CRITICAL 9.8
CVE-2019-1010275

helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because s…

Fix: 2.7.2+
Fix from $2,300 2019-07-17
Helm MEDIUM 6.5
CVE-2019-1000008

All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversa…

Fix: 2.12.2+
Fix from $1,600 2019-02-04
Chartmuseum MEDIUM 6.5
CVE-2019-1000009

Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulner…

Fix: 0.8.1+
Fix from $1,600 2019-02-04