CVE-2025-32386 - CVE House
Back to Database
Status published Medium CVE-2025-32386

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

Vulnerability Description

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved in Helm v3.17.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-32386

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

helm
Vulnerable Versions:
< 3.17.3

Timeline

Official Publish: April 9th, 2025
Last Modified: April 10th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Weaknesses (CWE)