---
id: CVE-2022-23526
title: 'helm: Denial of service through schema file (CVE-2022-23526)'
summary: >-
  A flaw was found in Helm, a tool for managing Charts, a pre-configured
  Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer
  Dereference in the_chartutil_ package that could cause a segmentation
  violation. The _chartut…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-476
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - cert_manager_operator_for_red_hat_openshift
  - openshift_developer_tools_and_services
  - openshift_serverless
  - openshift_service_mesh 2.1
  - openshift_service_mesh 2
  - 3scale_api_management_platform 2
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 3
  - openshift_container_platform 4
  - openshift_container_storage 4
  - openshift_container_platform 4.12
  - openshift_container_platform 4.13
  - openshift_container_platform 4.14
patched:
  - openshift_container_platform 4.12
  - openshift_container_platform 4.13
  - openshift_container_platform 4.14
published: '2022-12-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:34:50+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-23526.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-23526.json
  - url: 'https://access.redhat.com/security/cve/CVE-2022-23526'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2154196'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2022-23526'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23526'
  - url: >-
      https://github.com/helm/helm/commit/bafafa8bb1b571b61d7a9528da8d40c307dade3d
  - url: 'https://github.com/helm/helm/security/advisories/GHSA-67fx-wx78-jx33'
  - url: 'https://access.redhat.com/errata/RHSA-2023:1646'
  - url: 'https://access.redhat.com/errata/RHSA-2023:1326'
  - url: 'https://access.redhat.com/errata/RHSA-2023:5006'
  - url: 'https://github.com/helm/helm'
  - url: 'https://pkg.go.dev/vuln/GO-2022-1166'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
  - score-dispute
epss: 0.00818
epssPercentile: 0.55225
aliases:
  - GHSA-67fx-wx78-jx33
  - BIT-helm-2022-23526
  - GO-2022-1166
ecosystem: go
scores:
  vendor: 7.5
  osv: 5.3
ingestedAt: '2026-09-12T03:13:01.757Z'
---

## Overview

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The _chartutil_ package contains a parser that loads a JSON Schema validation files into structures Go can work with. Some schema files can cause array data structures to be created, causing a memory violation. Applications that use the _chartutil_ package in the Helm SDK to parse a schema files may result in a denial of service.

## Vendor advisories

- **RHSA-2023:1646** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2023-04-11 · [advisory](https://access.redhat.com/errata/RHSA-2023:1646)
- **RHSA-2023:1326** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2023-05-17 · [advisory](https://access.redhat.com/errata/RHSA-2023:1326)
- **RHSA-2023:5006** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2023-10-31 · [advisory](https://access.redhat.com/errata/RHSA-2023:5006)
- **Red Hat VEX** · Moderate · affected: cert-manager Operator for Red Hat OpenShift, OpenShift Developer Tools and Services, OpenShift Serverless, OpenShift Service Mesh 2.1, OpenShift Service Mesh 2, Red Hat 3scale API Management Platform 2, … · no fix planned: Red Hat Openshift Container Storage 4, cert-manager Operator for Red Hat OpenShift, OpenShift Developer Tools and Services, OpenShift Serverless, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-23526.json)

**helm: Denial of service through schema file** — rated Moderate by Red Hat. Released 2022-12-15, updated 2026-09-17.

Affected:

- cert-manager Operator for Red Hat OpenShift
- OpenShift Developer Tools and Services
- OpenShift Serverless
- OpenShift Service Mesh 2.1
- OpenShift Service Mesh 2
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 3
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Container Storage 4

Fixed:

- Red Hat OpenShift Container Platform 4.12
- Red Hat OpenShift Container Platform 4.13
- Red Hat OpenShift Container Platform 4.14

No fix planned:

- Red Hat Openshift Container Storage 4
- cert-manager Operator for Red Hat OpenShift
- OpenShift Developer Tools and Services
- OpenShift Serverless
- OpenShift Service Mesh 2.1
- OpenShift Service Mesh 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat OpenShift Container Platform 4
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Security 3

Not affected:

- Red Hat OpenShift Container Platform 4.12
- Red Hat OpenShift Container Platform 4.13
- Red Hat OpenShift Container Platform 4.14
- Cryostat 2
- Red Hat Ansible Automation Platform 1.2
- Red Hat Ansible Automation Platform 2
- Red Hat Openshift Data Foundation 4

## Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html https://access.redhat.com/errata/RHSA-2023:1646
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at
https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags

The sha values for the release are:

(For x8… https://access.redhat.com/errata/RHSA-2023:1326
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

      https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

      The sha values for the release … https://access.redhat.com/errata/RHSA-2023:5006

## Package advisory (CVE-2022-23526)

Affected packages:

- `helm.sh/helm/v3 < 3.10.3`

Patched in:

- `helm.sh/helm/v3 3.10.3`

Source: https://osv.dev/vulnerability/GHSA-67fx-wx78-jx33
