PT-2026-60806 · Helm+1 · Helm+1

·

CVE-2026-63308

·

Published

2026-07-17

·

Updated

2026-09-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Helm versions prior to 4.2.4
Description A denial of service issue exists in the Files.Lines template helper within pkg/engine/files.go. An attacker can trigger an index out of range panic by including zero-length byte slices in chart files. This allows for deterministic render failures during template, install, upgrade, lint, and SDK Engine.Render operations by including empty files in Helm charts.
Recommendations Update to version 4.2.4 or later to apply the fix implemented in commit ba6c9a2.

Exploit

Fix

DoS

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92991
BIT-HELM-2026-63308
CVE-2026-63308
OPENSUSE-SU-2026:11386-1
OPENSUSE-SU-2026:11387-1
OPENSUSE-SU-2026:21809-1
RHSA-2026:42230
RHSA-2026:42241
RHSA-2026:55180
SUSE-SU-2026:3882-1

Affected Products

Helm
Red Os