Allocation of Resources Without Limits or Throttling in Helm - CVE-2025-55199
Published: February 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can craft a JSON Schema file in a manner which could cause Helm to use all available memory and have an out of memory (OOM) termination.
Affected software
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
Containers Module
SUSE Package Hub 15
IBM Observability with Instana
helm-debuginfo
helm
helm-bash-completion
helm-zsh-completion
helm-fish-completion
How to mitigate CVE-2025-55199
IBM Observability with Instana - update to 1.0.307
helm-debuginfo - update to 3.20.2-150000.1.71.2
helm - update to 3.20.2-150000.1.71.2
helm-bash-completion - update to 3.20.2-150000.1.71.2
helm-zsh-completion - update to 3.20.2-150000.1.71.2
helm-fish-completion - update to 3.20.2-150000.1.71.2