Resource Exhaustion in Helm Tool by Tiller
CVE-2025-32386
6.5MEDIUM
What is CVE-2025-32386?
Helm, a widely used tool for managing Kubernetes package charts, is susceptible to a resource exhaustion vulnerability. When a specially crafted chart archive is loaded, it can expand significantly larger in uncompressed form than its compressed size. This discrepancy can lead to excessive memory consumption, potentially causing the Helm application to terminate unexpectedly. The issue has been addressed in Helm version 3.17.3, which mitigates the risk associated with this vulnerability, ensuring more stable performance when handling chart packages.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
helm < 3.17.3
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
