#VU123134 Use of uninitialized resource in Helm - CVE-2025-55198
Published: February 23, 2026
Helm
The Helm Project
Description
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to an improper validation of type error can lead to a panic when parsing Chart.yaml and index.yaml files. A remote attacker can pass specially crafted data to the application, trigger uninitialized usage of resources and bypass implemented security mechanisms.