helm records
30 published records for vendor helm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 96.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-18658No exploit | In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciouhelm · helm · CWE-59 | Critical9.8 | — | 1.7% | Nov 12, 2019 |
39Monitor | CVE-2019-1010275No exploit | helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation.helm · helm · CWE-295 | Critical9.8 | — | 1.4% | Jul 17, 2019 |
34Monitor | CVE-2021-32690No exploit | Repository credentials passed to alternate domainhelm · helm · CWE-200 | High8.6 | — | 1.4% | Jun 16, 2021 |
34Monitor | CVE-2025-53547Proof of concept | Helm Chart Dependency Updating With Malicious Chart.yaml Content And Symlink Can Lead To Code Executionhelm · helm · CWE-94 | High8.6 | — | 0.4% | Jul 8, 2025 |
33Monitor | CVE-2026-35205No exploit | Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin installhelm · helm · CWE-636 | High8.4 | — | 0.3% | Apr 9, 2026 |
33Monitor | CVE-2026-35204Proof of concept | Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directoryhelm · helm · CWE-22 | High8.4 | — | 0.2% | Apr 9, 2026 |
30Monitor | CVE-2022-36049No exploit | Flux2 Helm Controller denial of servicehelm · helm · CWE-400 | High7.5 | — | 1.4% | Sep 7, 2022 |
30Monitor | CVE-2024-26147No exploit | Helm's Missing YAML Content Leads To Panichelm · helm · CWE-457 | High7.5 | — | 0.9% | Feb 21, 2024 |
30Monitor | CVE-2022-23526No exploit | Helm contains Denial of service through schema filehelm · helm · CWE-476 | High7.5 | — | 0.9% | Dec 15, 2022 |
30Monitor | CVE-2022-23525No exploit | Helm vulnerable to Denial of service via NULL Pointer Dereferencehelm · helm · CWE-476 | High7.5 | — | 0.9% | Dec 15, 2022 |
30Monitor | CVE-2022-23524No exploit | Helm vulnerable to Denial of service through string value parsinghelm · helm · CWE-400 | High7.5 | — | 0.8% | Dec 15, 2022 |
27Monitor | CVE-2020-4053No exploit | Path Traversal in Helm Plugin Archivehelm · helm · CWE-22 | Medium6.8 | — | 1.5% | Jun 16, 2020 |
27Monitor | CVE-2021-21303No exploit | Injection attack in Helmhelm · helm · CWE-74 | Medium6.8 | — | 1.0% | Feb 5, 2021 |
26Monitor | CVE-2019-1000008No exploit | All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Pathhelm · helm · CWE-22 | Medium6.5 | — | 1.5% | Feb 4, 2019 |
26Monitor | CVE-2019-1000009No exploit | Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversalhelm · chartmuseum · CWE-22 | Medium6.5 | — | 1.3% | Feb 4, 2019 |
26Monitor | CVE-2022-36055No exploit | Denial of service in Helmhelm · helm · CWE-400 | Medium6.5 | — | 1.0% | Sep 1, 2022 |
26Monitor | CVE-2019-25210No exploit | An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3.helm · helm · CWE-200 | Medium6.5 | — | 0.7% | Mar 3, 2024 |
26Monitor | CVE-2025-32387No exploit | Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflowhelm · helm · CWE-121 | Medium6.5 | — | 0.5% | Apr 9, 2025 |
26Monitor | CVE-2025-32386No exploit | Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Terminationhelm · helm · CWE-770 | Medium6.5 | — | 0.4% | Apr 9, 2025 |
26Monitor | CVE-2025-55198No exploit | Helm May Panic Due To Incorrect YAML Contenthelm · helm · CWE-908 | Medium6.5 | — | 0.3% | Aug 13, 2025 |
26Monitor | CVE-2025-55199No exploit | Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustionhelm · helm · CWE-770 | Medium6.5 | — | 0.3% | Aug 13, 2025 |
25Monitor | CVE-2024-25620No exploit | Dependency management path traversal in helmhelm · helm · CWE-22 | Medium6.4 | — | 0.6% | Feb 14, 2024 |
21Monitor | CVE-2026-63308No exploit | Helm Files.Lines Denial of Service via Empty Chart Fileshelm · helm · CWE-129 | Medium5.3 | — | 0.5% | Jul 17, 2026 |
20Monitor | CVE-2020-11013No exploit | lookup Function Information Discolosure in Helmhelm · helm · CWE-200 | Medium5.0 | — | 1.3% | Apr 24, 2020 |
19Monitor | CVE-2026-35206No exploit | Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segmenthelm · helm · CWE-22 | Medium4.8 | — | 0.2% | Apr 9, 2026 |
- CVE-2019-1865840Plan
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciou
CriticalCVSS 9.8No exploitEPSS 2%helm · helmNov 12, 2019
- CVE-2019-101027539Monitor
helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation.
CriticalCVSS 9.8No exploitEPSS 1%helm · helmJul 17, 2019
- CVE-2021-3269034Monitor
Repository credentials passed to alternate domain
HighCVSS 8.6No exploitEPSS 1%helm · helmJun 16, 2021
- CVE-2025-5354734Monitor
Helm Chart Dependency Updating With Malicious Chart.yaml Content And Symlink Can Lead To Code Execution
HighCVSS 8.6Proof of conceptEPSS 0%helm · helmJul 8, 2025
- CVE-2026-3520533Monitor
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
HighCVSS 8.4No exploitEPSS 0%helm · helmApr 9, 2026
- CVE-2026-3520433Monitor
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
HighCVSS 8.4Proof of conceptEPSS 0%helm · helmApr 9, 2026
- CVE-2022-3604930Monitor
Flux2 Helm Controller denial of service
HighCVSS 7.5No exploitEPSS 1%helm · helmSep 7, 2022
- CVE-2024-2614730Monitor
Helm's Missing YAML Content Leads To Panic
HighCVSS 7.5No exploitEPSS 1%helm · helmFeb 21, 2024
- CVE-2022-2352630Monitor
Helm contains Denial of service through schema file
HighCVSS 7.5No exploitEPSS 1%helm · helmDec 15, 2022
- CVE-2022-2352530Monitor
Helm vulnerable to Denial of service via NULL Pointer Dereference
HighCVSS 7.5No exploitEPSS 1%helm · helmDec 15, 2022
- CVE-2022-2352430Monitor
Helm vulnerable to Denial of service through string value parsing
HighCVSS 7.5No exploitEPSS 1%helm · helmDec 15, 2022
- CVE-2020-405327Monitor
Path Traversal in Helm Plugin Archive
MediumCVSS 6.8No exploitEPSS 1%helm · helmJun 16, 2020
- CVE-2021-2130327Monitor
Injection attack in Helm
MediumCVSS 6.8No exploitEPSS 1%helm · helmFeb 5, 2021
- CVE-2019-100000826Monitor
All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path
MediumCVSS 6.5No exploitEPSS 1%helm · helmFeb 4, 2019
- CVE-2019-100000926Monitor
Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal
MediumCVSS 6.5No exploitEPSS 1%helm · chartmuseumFeb 4, 2019
- CVE-2022-3605526Monitor
Denial of service in Helm
MediumCVSS 6.5No exploitEPSS 1%helm · helmSep 1, 2022
- CVE-2019-2521026Monitor
An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3.
MediumCVSS 6.5No exploitEPSS 1%helm · helmMar 3, 2024
- CVE-2025-3238726Monitor
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
MediumCVSS 6.5No exploitEPSS 0%helm · helmApr 9, 2025
- CVE-2025-3238626Monitor
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
MediumCVSS 6.5No exploitEPSS 0%helm · helmApr 9, 2025
- CVE-2025-5519826Monitor
Helm May Panic Due To Incorrect YAML Content
MediumCVSS 6.5No exploitEPSS 0%helm · helmAug 13, 2025
- CVE-2025-5519926Monitor
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
MediumCVSS 6.5No exploitEPSS 0%helm · helmAug 13, 2025
- CVE-2024-2562025Monitor
Dependency management path traversal in helm
MediumCVSS 6.4No exploitEPSS 1%helm · helmFeb 14, 2024
- CVE-2026-6330821Monitor
Helm Files.Lines Denial of Service via Empty Chart Files
MediumCVSS 5.3No exploitEPSS 0%helm · helmJul 17, 2026
- CVE-2020-1101320Monitor
lookup Function Information Discolosure in Helm
MediumCVSS 5.0No exploitEPSS 1%helm · helmApr 24, 2020
- CVE-2026-3520619Monitor
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
MediumCVSS 4.8No exploitEPSS 0%helm · helmApr 9, 2026