PT-2025-33104 · Helm+1 · Helm+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Helm versions prior to 3.18.5
Description:
Helm, a package manager for Kubernetes Charts, is susceptible to a denial-of-service issue. A crafted JSON Schema file can cause Helm to exhaust available memory, leading to an out-of-memory (OOM) termination. This occurs when the
$ref field in values.schema.json points to a device or problematic file, such as /dev/zero.Recommendations:
Helm versions prior to 3.18.5 should be updated to version 3.18.5 or later.
Ensure all Helm charts loaded into Helm do not have any reference of
$ref pointing to /dev/zero.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helm
Red Os