Use of uninitialized resource in Helm - CVE-2025-55198

 

Use of uninitialized resource in Helm - CVE-2025-55198

Published: February 23, 2026


Vulnerability identifier: #VU123134
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-55198
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to an improper validation of type error can lead to a panic when parsing Chart.yaml and index.yaml files. A remote attacker can pass specially crafted data to the application, trigger uninitialized usage of resources and bypass implemented security mechanisms.


Affected software

Helm
IBM Observability with Instana

How to mitigate CVE-2025-55198

Install updates from vendor's website.

Helm - update to 3.18.5
IBM Observability with Instana - update to 1.0.307

External References

Related Security Bulletins