CVE-2025-55199

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring all Helm charts that are being loaded into Helm do not have any reference of $ref pointing to /dev/zero.
Configurations

Configuration 1 (hide)

cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*

History

21 Aug 2025, 21:25

Type Values Removed Values Added
References () https://github.com/helm/helm/commit/b78692c18f0fb38fe5ba4571a674de067a4c53a5 - () https://github.com/helm/helm/commit/b78692c18f0fb38fe5ba4571a674de067a4c53a5 - Patch
References () https://github.com/helm/helm/security/advisories/GHSA-9h84-qmv7-982p - () https://github.com/helm/helm/security/advisories/GHSA-9h84-qmv7-982p - Third Party Advisory
CPE cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*
First Time Helm
Helm helm

14 Aug 2025, 13:11

Type Values Removed Values Added
Summary
  • (es) Helm es un gestor de paquetes para gráficos de Kubernetes. Antes de la versión 3.18.5, era posible manipular un archivo de esquema JSON que pudiera provocar que Helm utilizara toda la memoria disponible y terminara por falta de memoria (OOM). Este problema se ha resuelto en Helm 3.18.5. Una solución alternativa consiste en garantizar que todos los gráficos de Helm que se cargan en Helm no tengan ninguna referencia de $ref que apunte a /dev/zero.

14 Aug 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-14 00:15

Updated : 2025-08-21 21:25


NVD link : CVE-2025-55199

Mitre link : CVE-2025-55199

CVE.ORG link : CVE-2025-55199


JSON object : View

Products Affected

helm

  • helm
CWE
CWE-770

Allocation of Resources Without Limits or Throttling