Allocation of Resources Without Limits or Throttling in Helm - CVE-2025-32386

 

Allocation of Resources Without Limits or Throttling in Helm - CVE-2025-32386

Published: June 30, 2025


Vulnerability identifier: #VU112039
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32386
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). A remote attacker can trick the victim into opening this specially crafted chart to cause memory exhaustion and the application to be terminated.


Affected software

Helm
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Containers Module
openSUSE Leap
Kubecost Self Hosted
IBM Cloud Pak for Watson AIOps
IBM Fusion HCI
Cloud Pak for Data
helm-mirror-debuginfo
helm-mirror

How to mitigate CVE-2025-32386

Install updates from vendor's website.

Helm - update to 3.17.3
IBM Fusion HCI - update to 2.11.0
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Cloud Pak for Data - update to 5.0.1
helm-mirror-debuginfo - update to 0.3.1-150000.1.18.2
helm-mirror - update to 0.3.1-150000.1.18.2

External References

Related Security Bulletins