#VU112039 Allocation of Resources Without Limits or Throttling in Helm - CVE-2025-32386
Published: June 30, 2025
Helm
The Helm Project
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). A remote attacker can trick the victim into opening this specially crafted chart to cause memory exhaustion and the application to be terminated.