Bug 2501801 (CVE-2026-63308) - CVE-2026-63308 Helm: Helm: Denial of Service via malformed chart files
Summary: CVE-2026-63308 Helm: Helm: Denial of Service via malformed chart files
Keywords:
Status: NEW
Alias: CVE-2026-63308
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-17 17:01 UTC by OSIDB Bzimport
Modified: 2026-08-25 14:59 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-17 17:01:43 UTC
Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations.


Note You need to log in before you can comment on or make changes to this bug.