PT-2025-15873 · Helm+2 · Helm+2

Jake-Ciolek

·

Published

2025-04-09

·

Updated

2026-01-03

·

CVE-2025-32387

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Helm versions prior to 3.17.3
Description: A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. This issue was discovered by a Helm contributor.
Recommendations: For versions prior to 3.17.3, update to Helm v3.17.3 to resolve the issue. As a temporary workaround, ensure that the JSON Schema within any charts loaded by Helm does not have a large number of nested references, specifically avoiding files larger than 10 MiB.

Exploit

Fix

DoS

Stack Overflow

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

AZL-59979
AZL-60172
BDU:2025-06056
BIT-HELM-2025-32387
CVE-2025-32387
GHSA-5XQW-8HWV-WG92
GO-2025-3602
OPENSUSE-SU-2025:14995-1
SUSE-SU-2025:01830-1
SUSE-SU-2025:01830-2

Affected Products

Helm
Red Os
Suse