helm has 13 CVEs on record between 2021 and 2026. The busiest recent month was April 2026 with 3. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. Most affected products: helm.sh/helm/v3 (10), helm.sh/helm/v4 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
Products
- helm.sh/helm/v3 10
- helm.sh/helm/v4 3
Worst active — by depth score
CVE-2026-35204High· 8.6Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory59CVE-2026-35205High· 7.8Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install43CVE-2025-32387Medium· 6.5Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow36CVE-2025-32386Medium· 6.5Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination36CVE-2022-36055Medium· 6.5Helm Vulnerable to denial of service through string value parsing36
helm vulnerabilities
CVEs affecting helm, newest first. Open any entry for full detail, references, and exploit status.
13 CVEsRSS
CVE-2026-35204High· 8.6PoCHelm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
CVE-2026-35205High· 7.8Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
CVE-2026-35206MediumHelm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
CVE-2025-32387Medium· 6.5Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
CVE-2025-32386Medium· 6.5Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
CVE-2022-36055Medium· 6.5Helm Vulnerable to denial of service through string value parsing
Helm Vulnerable to denial of service through string value parsing
CVE-2020-4053Low· 3.7Plugin archive directory traversal in Helm
Plugin archive directory traversal in Helm
CVE-2021-21303Medium· 6.5Improper Neutralization of Special Elements in Output in helm.sh/helm/v3
Improper Neutralization of Special Elements in Output in helm.sh/helm/v3
CVE-2021-32690MediumHelm passes repository credentials to alternate domain
Helm passes repository credentials to alternate domain
CVE-2020-15186Low· 3.4Improper Sanitizing of plugin names in helm
Improper Sanitizing of plugin names in helm
CVE-2020-15185Low· 2.2Repository index file allows for duplicates of the same chart entry in helm
Repository index file allows for duplicates of the same chart entry in helm
CVE-2020-15187Low· 3.0plugin.yaml file allows for duplicate entries in helm
plugin.yaml file allows for duplicate entries in helm
CVE-2020-15184Low· 3.7Aliases are never checked in helm
Aliases are never checked in helm