VDB
GO-2025-3602
GO-2025-3602
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | rancher-helm-3 | 0, 0 |
| chainguard | flux-helm-controller-fips | 0, 0 |
| chainguard | helm-docs | 0 |
| chainguard | cert-manager-cmctl-fips | 0, 0 |
| chainguard | harbor-fips-2.11 | 0 |
| chainguard | eksctl | 0, 0 |
| chainguard | helm-push | 0 |
| chainguard | k9s | 0, 0 |
| chainguard | cert-manager-cmctl | 0, 0 |
| chainguard | chartmuseum-fips | 0, 0 |
| chainguard | chart-testing | 0, 0 |
| wolfi | kots | 0, 0, 0 |
| chainguard | harbor-2.12 | 0 |
| wolfi | kubescape | 0, 0, 0 |
| wolfi | chart-testing | 0, 0, 0 |
| chainguard | consul-k8s-fips-1.4 | 0, 0 |
| chainguard | flux-helm-controller | 0, 0 |
| chainguard | k8ssandra-client-fips | 0, 0 |
| chainguard | kuma-2.7 | 0, 0 |
| wolfi | cilium-cli | 0, 0, 0 |
…and 44 more
Timeline
- Apr 10, 2025 CVE Published
- Feb 4, 2026 CVE Updated