VDB

GO-2025-3802

GO-2025-3802 PUBLISHED

Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm

Affected Products

VendorProductVersions
chainguardflux-fips-2.50, 0, 0
chainguardconsul-k8s-1.40, 0, 0
wolfik8ssandra-client0, 0, 0
chainguardk8ssandra-client-fips0, 0, 0
chainguardzot0, 0, 0
wolfikots0, 0, 0
wolfienvoy-gateway0, 0, 0
wolfitw0, 0, 0
wolfihelm-docs0, 0, 0
chainguardrancher-fleet-fips0, 0, 0
wolfik9s0, 0, 0
chainguardeksctl0, 0, 0
chainguardconsul-k8s-fips-1.60, 0, 0
chainguardteleport-150, 0, 0
helm.shhelm/v30, 0
wolfikargo0, 0, 0
chainguardk9s0, 0, 0
chainguardenvoy-gateway-fips0, 0, 0
chainguardtrivy0, 0, 0
chainguardconsul-k8s-fips-1.50, 0, 0

…and 77 more

Timeline

  • Jul 21, 2025 CVE Published
  • Feb 4, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›