{"id":"CVE-2022-23525","title":"helm: Denial of service through through repository index file (CVE-2022-23525)","summary":"A flaw was found in Helm. Applications that use the _repo_ package in Helm SDK to parse an index file may suffer a denial of service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index fil…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-476","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.14","affected":["cert_manager_operator_for_red_hat_openshift","openshift_developer_tools_and_services","openshift_serverless","3scale_api_management_platform 2","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 3","openshift_container_platform 4","openshift_container_storage 4","openshift_container_platform 4.12","openshift_container_platform 4.13","openshift_container_platform 4.14"],"patched":["openshift_container_platform 4.12","openshift_container_platform 4.13","openshift_container_platform 4.14"],"published":"2022-12-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:34:39+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-23525.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-23525.json"},{"url":"https://access.redhat.com/security/cve/CVE-2022-23525"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2154202"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-23525"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23525"},{"url":"https://github.com/helm/helm/commit/638ebffbc2e445156f3978f02fd83d9af1e56f5b"},{"url":"https://github.com/helm/helm/security/advisories/GHSA-53c4-hhmh-vw5q"},{"url":"https://access.redhat.com/errata/RHSA-2023:1646"},{"url":"https://access.redhat.com/errata/RHSA-2023:1326"},{"url":"https://access.redhat.com/errata/RHSA-2023:5006"},{"url":"https://github.com/helm/helm"},{"url":"https://pkg.go.dev/vuln/GO-2022-1165"}],"tags":["csaf","vex","red-hat","osv","go","score-dispute"],"epss":0.00818,"epssPercentile":0.55662,"aliases":["GHSA-53c4-hhmh-vw5q","BIT-helm-2022-23525","GO-2022-1165"],"ecosystem":"go","scores":{"vendor":7.5,"osv":5.3},"ingestedAt":"2026-09-12T03:13:01.754Z","slug":"CVE-2022-23525","body":"## Overview\n\nA flaw was found in Helm. Applications that use the _repo_ package in Helm SDK to parse an index file may suffer a denial of service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index file that causes a memory violation panic.\n\n## Vendor advisories\n\n- **RHSA-2023:1646** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2023-04-11 · [advisory](https://access.redhat.com/errata/RHSA-2023:1646)\n- **RHSA-2023:1326** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2023-05-17 · [advisory](https://access.redhat.com/errata/RHSA-2023:1326)\n- **RHSA-2023:5006** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2023-10-31 · [advisory](https://access.redhat.com/errata/RHSA-2023:5006)\n- **Red Hat VEX** · Moderate · affected: cert-manager Operator for Red Hat OpenShift, OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat 3scale API Management Platform 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Security 3, … · no fix planned: Red Hat Openshift Container Storage 4, cert-manager Operator for Red Hat OpenShift, OpenShift Developer Tools and Services, OpenShift Serverless, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-23525.json)\n\n**helm: Denial of service through through repository index file** — rated Moderate by Red Hat. Released 2022-12-15, updated 2026-09-17.\n\nAffected:\n\n- cert-manager Operator for Red Hat OpenShift\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 3\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Container Storage 4\n\nFixed:\n\n- Red Hat OpenShift Container Platform 4.12\n- Red Hat OpenShift Container Platform 4.13\n- Red Hat OpenShift Container Platform 4.14\n\nNo fix planned:\n\n- Red Hat Openshift Container Storage 4\n- cert-manager Operator for Red Hat OpenShift\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat OpenShift Container Platform 4\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Security 3\n\nNot affected:\n\n- Red Hat OpenShift Container Platform 4.12\n- Red Hat OpenShift Container Platform 4.13\n- Red Hat OpenShift Container Platform 4.14\n- Cryostat 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat Openshift Data Foundation 4\n\n## Remediation\n\nFor OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html https://access.redhat.com/errata/RHSA-2023:1646\nFor OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html\n\nYou may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at\nhttps://quay.io/repository/openshift-release-dev/ocp-release?tab=tags\n\nThe sha values for the release are:\n\n(For x8… https://access.redhat.com/errata/RHSA-2023:1326\nFor OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:\n\n      https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html\n\nYou may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.\n\n      The sha values for the release … https://access.redhat.com/errata/RHSA-2023:5006\n\n## Package advisory (CVE-2022-23525)\n\nAffected packages:\n\n- `helm.sh/helm/v3 < 3.10.3`\n\nPatched in:\n\n- `helm.sh/helm/v3 3.10.3`\n\nSource: https://osv.dev/vulnerability/GHSA-53c4-hhmh-vw5q","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[{"seq":206310,"id":"CVE-2022-23525","ts":1789663198100,"field":"cvss","old":"5.3","new":"7.5"},{"seq":206309,"id":"CVE-2022-23525","ts":1789663198100,"field":"severity","old":"medium","new":"high"}]}