Allocation of Resources Without Limits or Throttling in Helm - CVE-2025-55199

 

Allocation of Resources Without Limits or Throttling in Helm - CVE-2025-55199

Published: February 23, 2026


Vulnerability identifier: #VU123133
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-55199
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination.


Affected software

Helm
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
Containers Module
SUSE Package Hub 15
IBM Observability with Instana
helm-debuginfo
helm
helm-bash-completion
helm-zsh-completion
helm-fish-completion

How to mitigate CVE-2025-55199

Install updates from vendor's website.

Helm - update to 3.18.5
IBM Observability with Instana - update to 1.0.307
helm-debuginfo - update to 3.20.2-150000.1.71.2
helm - update to 3.20.2-150000.1.71.2
helm-bash-completion - update to 3.20.2-150000.1.71.2
helm-zsh-completion - update to 3.20.2-150000.1.71.2
helm-fish-completion - update to 3.20.2-150000.1.71.2

External References

Related Security Bulletins