Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10671 | Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow |
Github GHSA |
GHSA-5xqw-8hwv-wg92 | Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow |
Wed, 03 Sep 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* |
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Apr 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 09 Apr 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. This issue has been resolved in Helm v3.17.3. | |
| Title | Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow | |
| Weaknesses | CWE-121 CWE-674 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-10T14:58:47.796Z
Reserved: 2025-04-06T19:46:02.463Z
Link: CVE-2025-32387
Updated: 2025-04-10T14:58:34.576Z
Status : Analyzed
Published: 2025-04-09T23:15:37.903
Modified: 2025-09-03T17:03:46.233
Link: CVE-2025-32387
OpenCVE Enrichment
Updated: 2025-07-12T16:01:46Z
EUVD
Github GHSA