Stack Overflow Vulnerability in Helm Package Manager for Kubernetes
CVE-2025-32387
6.5MEDIUM
What is CVE-2025-32387?
Helm, a package manager for Kubernetes, is susceptible to a stack overflow vulnerability due to a maliciously crafted JSON Schema file. This file can contain a deeply nested chain of references, which triggers extensive parser recursion, ultimately exceeding the stack size limit. Users are urged to update to Helm version 3.17.3 or later to address this issue and enhance the security of their Kubernetes environments.
Affected Version(s)
helm < 3.17.3
