Loading HuntDB...

GHSA-53c4-hhmh-vw5q

GitHub Security Advisory

Helm vulnerable to denial of service through through repository index file

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the `_repo_` package that can cause a segmentation violation. Applications that use functions from the `_repo_` package in the Helm SDK can have a Denial of Service attack when they use this package and it panics.

### Impact

The `_repo_` package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The `_repo_` package parses the index file of the repository and loads it into structures Go can work with. Some index files can cause array data structures to be created causing a memory violation.

Applications that use the `_repo_` package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from.

The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client.

### Patches

This issue has been resolved in 3.10.3.

### Workarounds

SDK users can validate index files that are correctly formatted before passing them to the `_repo_` functions.

### For more information

Helm's security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document.

### Credits

Disclosed by Ada Logics in a fuzzing audit sponsored by CNCF.

Affected Packages

Go helm.sh/helm/v3
Affected versions: 0 (fixed in 3.10.3)

Related CVEs

Key Information

GHSA ID
GHSA-53c4-hhmh-vw5q
Published
December 14, 2022 9:38 PM
Last Modified
August 30, 2023 6:40 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
helm.sh/helm/v3
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 1, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.