VDB

CVE-2025-32387

CVE-2025-32387 PUBLISHED CVSS 6.5 MEDIUM

Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. This issue has been resolved in Helm v3.17.3.

EPSS 0.46% · 37.9th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
0.46%
37.9th percentile

Affected Products

VendorProductVersions
Bitnamihelm0
Bitnamihelm0

Timeline

  • Jan 21, 1970 Security Advisory
  • Apr 9, 2025 CVE Published
  • Apr 10, 2025 EPSS Score
  • Apr 23, 2025 EPSS Score
  • May 5, 2025 EPSS Score
  • May 12, 2025 Coalition ESS Score
  • May 18, 2025 EPSS Score
  • May 31, 2025 EPSS Score
  • Jun 12, 2025 EPSS Score
  • Jun 25, 2025 EPSS Score
  • Jul 8, 2025 EPSS Score
  • Jul 21, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›