helm.sh/helm/v3 vulnerabilities
CVEs whose affected-version data names the helm.sh/helm/v3 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
11 CVEsRSS
CVE-2026-35206MediumHelm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
CVE-2025-32387Medium· 6.5Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
CVE-2025-32386Medium· 6.5Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
CVE-2022-36055Medium· 6.5Helm Vulnerable to denial of service through string value parsing
Helm Vulnerable to denial of service through string value parsing
CVE-2020-4053Low· 3.7Plugin archive directory traversal in Helm
Plugin archive directory traversal in Helm
CVE-2021-21303Medium· 6.5Improper Neutralization of Special Elements in Output in helm.sh/helm/v3
Improper Neutralization of Special Elements in Output in helm.sh/helm/v3
CVE-2021-32690MediumHelm passes repository credentials to alternate domain
Helm passes repository credentials to alternate domain
CVE-2020-15186Low· 3.4Improper Sanitizing of plugin names in helm
Improper Sanitizing of plugin names in helm
CVE-2020-15185Low· 2.2Repository index file allows for duplicates of the same chart entry in helm
Repository index file allows for duplicates of the same chart entry in helm
CVE-2020-15187Low· 3.0plugin.yaml file allows for duplicate entries in helm
plugin.yaml file allows for duplicate entries in helm
CVE-2020-15184Low· 3.7Aliases are never checked in helm
Aliases are never checked in helm