CVE Tools

Helm

9 CVEs tracked since 2019. Since Feb 2019, none of them reached CISA KEV.

Helm CVEs per month

Feb 2019 to Dec 2022. Point at a month, or focus the strip and use the arrow keys.
Helm CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-0220
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-0940
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-1230

Products

The products that kept showing up in Helm's monthly top three, with their CVEs summed over those months.

  1. Helm83 months
  2. Chartmuseum11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Helm.

  1. CVE-2026-63308Helm Files.Lines Denial of Service via Empty Chart Files4.3
  2. CVE-2026-35206Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment4.4
  3. CVE-2026-35205Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install7.8
  4. CVE-2026-35204Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory8.6
  5. CVE-2025-55198Helm May Panic Due To Incorrect YAML Content6.5
  6. CVE-2025-55199Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion6.5
  7. CVE-2025-53547Helm Chart Dependency Updating With Malicious Chart.yaml Content And Symlink Can Lead To Code Execution8.5
  8. CVE-2025-32386Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination6.5
  9. CVE-2025-32387Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow6.5
  10. CVE-2019-25210An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases,...6.5
  11. CVE-2024-26147Helm's Missing YAML Content Leads To Panic7.5
  12. CVE-2024-25620Dependency management path traversal in helm6.4
  13. CVE-2023-25165getHostByName Function Information Disclosure4.3
  14. CVE-2022-23526Helm contains Denial of service through schema file5.3
  15. CVE-2022-23525Helm vulnerable to Denial of service via NULL Pointer Dereference5.3

The record

Peak rank
#92 in Sep 2020
Busiest month shown
Sep 2020, 4 CVEs
Months with a KEV entry
0 since Feb 2019
Monthly snapshots
3 since 2019
Helm's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store