Database/Container, Kubernetes & orchestration
Helm: Decompression bomb chart exhausts memory on the rendering host
CVSS 6.5CVE-2025-32386Container, Kubernetes & orchestrationcurated
Impact
Decompression bomb chart exhausts memory on the rendering host
Who can reach it
Malicious chart
What to do
Upgrade Helm
References
Related entries
- Helm: Deeply nested JSON Schema references cause stack overflowCVE-2025-32387 · HelmMedium
- Helm: Crafted JSON Schema causes OOM termination of the rendererCVE-2025-55199 · HelmMedium
- Helm: Relative path in a chart name writes the chart outside the intended directoryCVE-2024-25620 · HelmMedium
- Helm: Improper certificate validation allows unauthorized clients to connect to TillerCVE-2019-1010275 · HelmCritical
- Helm: Malicious chart includes sensitive host content such as /etc/passwd, or triggers DoS, when loadedCVE-2019-18658 · HelmCritical
- Helm: The `lookup` template function discloses in-cluster resources, including Secrets, to a chart authorCVE-2020-11013 · HelmHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.