Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations.
References
| Link | Resource |
|---|---|
| https://github.com/helm/helm/commit/ba6c9a29efa7bf9198dad6a5ec12b4fb30c96017 | Patch |
| https://github.com/helm/helm/issues/32279 | Exploit Issue Tracking |
| https://github.com/helm/helm/pull/32290 | Issue Tracking Patch |
| https://www.vulncheck.com/advisories/chat2db-insecure-direct-object-reference-via-get-api-connection-datasource | Not Applicable |
Configurations
History
30 Jul 2026, 18:11
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* | |
| First Time |
Helm
Helm helm |
|
| References | () https://github.com/helm/helm/commit/ba6c9a29efa7bf9198dad6a5ec12b4fb30c96017 - Patch | |
| References | () https://github.com/helm/helm/issues/32279 - Exploit, Issue Tracking | |
| References | () https://github.com/helm/helm/pull/32290 - Issue Tracking, Patch | |
| References | () https://www.vulncheck.com/advisories/chat2db-insecure-direct-object-reference-via-get-api-connection-datasource - Not Applicable |
17 Jul 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-17 17:17
Updated : 2026-07-30 18:11
NVD link : CVE-2026-63308
Mitre link : CVE-2026-63308
CVE.ORG link : CVE-2026-63308
JSON object : View
Products Affected
helm
- helm
CWE
CWE-129
Improper Validation of Array Index
