
Cloud Vulnerability DB
A community-led vulnerabilities database
Helm, a package manager for Charts for Kubernetes, was found to contain a vulnerability (CVE-2025-55199) that could lead to memory exhaustion. Prior to version 3.18.5, it was possible for attackers to craft a JSON Schema file in a way that would cause Helm to consume all available memory, resulting in an out-of-memory (OOM) termination. The vulnerability was discovered by Jakub Ciolek at AlphaSense and was disclosed on August 13, 2025 (GitHub Advisory).
The vulnerability stems from the way Helm handles JSON Schema files, specifically when processing $ref pointers. An attacker could create a malicious chart that points $ref in values.schema.json to a device (e.g., /dev/*) or other problematic file, triggering excessive memory consumption during Helm Chart validation. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating network attack vector, low attack complexity, no privileges required, and high impact on availability (NVD).
The primary impact of this vulnerability is on system availability. When successfully exploited, the vulnerability can cause Helm to consume all available memory resources, leading to an out-of-memory (OOM) termination. This could potentially disrupt Kubernetes deployment processes and affect system operations (GitHub Advisory).
The vulnerability requires user interaction to process a maliciously crafted Helm chart. While no authentication is required, the attack vector is network-accessible, making it potentially exploitable in scenarios where users can be convinced to process untrusted Helm charts (GitHub Advisory).
The vulnerability has been patched in Helm version 3.18.5. For users unable to upgrade immediately, a workaround is available: ensure that all Helm charts being loaded into Helm do not have any reference of $ref pointing to /dev/zero. Users are strongly encouraged to upgrade to the patched version to ensure complete protection (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."