VulnSea

helm has 13 CVEs on record between 2021 and 2026. The busiest recent month was April 2026 with 3. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. Most affected products: helm.sh/helm/v3 (10), helm.sh/helm/v4 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
0 prev 3

Products

  • helm.sh/helm/v3 10
  • helm.sh/helm/v4 3
13
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

helm vulnerabilities

CVEs affecting helm, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2026-35204High· 8.6PoC
5mo ago

Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory

Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory

Midnighthelm · helm.sh/helm/v4EPSS 0.20%via OSV
CVE-2026-35205High· 7.8
5mo ago

Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install

Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install

Twilighthelm · helm.sh/helm/v4EPSS 0.22%via OSV
CVE-2026-35206Medium
5mo ago

Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

Sunlithelm · helm.sh/helm/v4EPSS 0.20%via OSV
CVE-2025-32387Medium· 6.5
1y ago

Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow

Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow

Sunlithelm · helm.sh/helm/v3EPSS 0.48%via OSV
CVE-2025-32386Medium· 6.5
1y ago

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

Sunlithelm · helm.sh/helm/v3EPSS 0.45%via OSV
CVE-2022-36055Medium· 6.5
4y ago

Helm Vulnerable to denial of service through string value parsing

Helm Vulnerable to denial of service through string value parsing

Sunlithelm · helm.sh/helm/v3EPSS 1.0%via OSV
CVE-2020-4053Low· 3.7
5y ago

Plugin archive directory traversal in Helm

Plugin archive directory traversal in Helm

Sunlithelm · helm.sh/helm/v3EPSS 1.5%via OSV
CVE-2021-21303Medium· 6.5
5y ago

Improper Neutralization of Special Elements in Output in helm.sh/helm/v3

Improper Neutralization of Special Elements in Output in helm.sh/helm/v3

Sunlithelm · helm.sh/helm/v3EPSS 1.0%via OSV
CVE-2021-32690Medium
5y ago

Helm passes repository credentials to alternate domain

Helm passes repository credentials to alternate domain

Sunlithelm · helm.sh/helm/v3EPSS 1.4%via OSV
CVE-2020-15186Low· 3.4
5y ago

Improper Sanitizing of plugin names in helm

Improper Sanitizing of plugin names in helm

Sunlithelm · helm.sh/helm/v3EPSS 0.96%via OSV
CVE-2020-15185Low· 2.2
5y ago

Repository index file allows for duplicates of the same chart entry in helm

Repository index file allows for duplicates of the same chart entry in helm

Sunlithelm · helm.sh/helm/v3EPSS 0.88%via OSV
CVE-2020-15187Low· 3.0
5y ago

plugin.yaml file allows for duplicate entries in helm

plugin.yaml file allows for duplicate entries in helm

Sunlithelm · helm.sh/helm/v3EPSS 1.5%via OSV
CVE-2020-15184Low· 3.7
5y ago

Aliases are never checked in helm

Aliases are never checked in helm

Sunlithelm · helm.sh/helm/v3EPSS 1.0%via OSV
helm vulnerabilities (CVEs) · VulnSea