CVE-2025-55198 – Helm Chart YAML Parsing Type Error Denial of Service

The following table lists the changes that have been made to the
CVE-2025-55198 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 14, 2025

    Action Type Old Value New Value
    Added Description Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround involves ensuring YAML files are formatted as Helm expects prior to processing them with Helm.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
    Added CWE CWE-908
    Added Reference https://github.com/helm/helm/commit/ec5f59e2db56533d042a124f5bae54dd87b558e6
    Added Reference https://github.com/helm/helm/security/advisories/GHSA-f9f8-9pmf-xv68
Share the Post:

Related Posts