PT-2026-60806 · Helm+1 · Helm+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Helm versions prior to 4.2.4
Description
A denial of service issue exists in the
Files.Lines template helper within pkg/engine/files.go. An attacker can trigger an index out of range panic by including zero-length byte slices in chart files. This allows for deterministic render failures during template, install, upgrade, lint, and SDK Engine.Render operations by including empty files in Helm charts.Recommendations
Update to version 4.2.4 or later to apply the fix implemented in commit ba6c9a2.
Exploit
Fix
DoS
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helm
Red Os