github.com
https://github.com/helm/helm CVE-2025-55199
MEDIUM
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
Record summary
CVE-2025-55199 has a selected CVSS score of 6.5 (medium).
Description
Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring all Helm charts that are being loaded into Helm do not have any reference of $ref pointing to /dev/zero.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 14, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 3.18.5 | affected | |
helm.sh/helm/v3Browse Go / helm.sh/helm/v3 | GitHub Advisory | Before 3.18.5 · Fixed in 3.18.5 | affected |
References
4github.com
https://github.com/helm/helm/commit/b78692c18f0fb38fe5ba4571a674de067a4c53a5 github.comConfirmation
https://github.com/helm/helm/security/advisories/GHSA-9h84-qmv7-982p nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-55199