CVE-2025-55199
Helm vulnerability analysis and mitigation

Overview

Helm, a package manager for Charts for Kubernetes, was found to contain a vulnerability (CVE-2025-55199) that could lead to memory exhaustion. Prior to version 3.18.5, it was possible for attackers to craft a JSON Schema file in a way that would cause Helm to consume all available memory, resulting in an out-of-memory (OOM) termination. The vulnerability was discovered by Jakub Ciolek at AlphaSense and was disclosed on August 13, 2025 (GitHub Advisory).

Technical details

The vulnerability stems from the way Helm handles JSON Schema files, specifically when processing $ref pointers. An attacker could create a malicious chart that points $ref in values.schema.json to a device (e.g., /dev/*) or other problematic file, triggering excessive memory consumption during Helm Chart validation. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating network attack vector, low attack complexity, no privileges required, and high impact on availability (NVD).

Impact

The primary impact of this vulnerability is on system availability. When successfully exploited, the vulnerability can cause Helm to consume all available memory resources, leading to an out-of-memory (OOM) termination. This could potentially disrupt Kubernetes deployment processes and affect system operations (GitHub Advisory).

Exploitability

The vulnerability requires user interaction to process a maliciously crafted Helm chart. While no authentication is required, the attack vector is network-accessible, making it potentially exploitable in scenarios where users can be convinced to process untrusted Helm charts (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Helm version 3.18.5. For users unable to upgrade immediately, a workaround is available: ensure that all Helm charts being loaded into Helm do not have any reference of $ref pointing to /dev/zero. Users are strongly encouraged to upgrade to the patched version to ensure complete protection (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Helm vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-53492HIGH8.4
  • Packer logoPacker
  • livekit-cli-fips
NoYesJul 01, 2026
CVE-2026-53489HIGH8.2
  • Packer logoPacker
  • kubevela
NoYesJul 01, 2026
CVE-2026-56852HIGH7.5
  • cAdvisor logocAdvisor
  • amazon-cloudwatch-agent
NoYesJul 21, 2026
CVE-2026-63308MEDIUM5.3
  • Helm logoHelm
  • helm-4
NoYesJul 17, 2026
CVE-2026-48978LOW2.1
  • Helm logoHelm
  • vcluster
NoYesJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management