{"schema_version":1,"title":"helm.sh/helm/v3 (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 23 vulnerabilities in helm.sh/helm/v3 (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-35206, was published on 10 April 2026.","url":"https://junglewise.ai/threats/technologies/helm-sh-helm-v3","json_url":"https://junglewise.ai/threats/technologies/helm-sh-helm-v3.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/helm-sh-helm-v3","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":23,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":1},"latest":[{"cve":"CVE-2026-35206","cvss":4,"epss":0.002,"slug":"cve-2026-35206-helm-path-traversal-via-chart-yaml-name-dot-segment","title":"Helm path traversal via Chart.yaml name dot-segment","severity":"medium","exploited":false,"published_at":"2026-04-10T15:33:09+00:00","url":"https://junglewise.ai/threats/cve-2026-35206-helm-path-traversal-via-chart-yaml-name-dot-segment"},{"cve":"CVE-2025-55198","cvss":3.1,"epss":0.0033,"slug":"cve-2025-55198-helm-may-panic-due-to-incorrect-yaml-content","title":"GO-2025-3888 - Helm May Panic Due To Incorrect YAML Content in helm.sh/helm","severity":"low","exploited":false,"published_at":"2025-08-18T19:03:35+00:00","url":"https://junglewise.ai/threats/cve-2025-55198-helm-may-panic-due-to-incorrect-yaml-content"},{"cve":"CVE-2025-55199","cvss":3.1,"epss":0.0033,"slug":"cve-2025-55199-helm-charts-with-specific-json-schema-values-can-cause-memory","title":"GO-2025-3887 - Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm","severity":"low","exploited":false,"published_at":"2025-08-18T19:03:32+00:00","url":"https://junglewise.ai/threats/cve-2025-55199-helm-charts-with-specific-json-schema-values-can-cause-memory"},{"cve":"CVE-2025-53547","cvss":3.1,"epss":0.0038,"slug":"cve-2025-53547-helm-vulnerable-to-code-injection-through-malicious-chart-yaml","title":"GO-2025-3802 - Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm","severity":"low","exploited":false,"published_at":"2025-07-21T15:05:07+00:00","url":"https://junglewise.ai/threats/cve-2025-53547-helm-vulnerable-to-code-injection-through-malicious-chart-yaml"},{"cve":"CVE-2025-32386","cvss":3.1,"epss":0.0045,"slug":"cve-2025-32386-helm-allows-a-specially-crafted-chart-archive-to-cause-out-of","title":"GO-2025-3601 - Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm","severity":"low","exploited":false,"published_at":"2025-04-10T16:27:06+00:00","url":"https://junglewise.ai/threats/cve-2025-32386-helm-allows-a-specially-crafted-chart-archive-to-cause-out-of"},{"cve":"CVE-2025-32387","cvss":3.1,"epss":0.0048,"slug":"cve-2025-32387-helm-allows-a-specially-crafted-json-schema-to-cause-a-stack","title":"GO-2025-3602 - Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm","severity":"low","exploited":false,"published_at":"2025-04-10T16:27:06+00:00","url":"https://junglewise.ai/threats/cve-2025-32387-helm-allows-a-specially-crafted-json-schema-to-cause-a-stack"},{"cve":"CVE-2024-26147","cvss":3.1,"epss":0.0093,"slug":"cve-2024-26147-helm-s-missing-yaml-content-leads-to-panic","title":"GO-2024-2575 - Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2024-06-04T15:19:21+00:00","url":"https://junglewise.ai/threats/cve-2024-26147-helm-s-missing-yaml-content-leads-to-panic"},{"cve":"CVE-2019-25210","cvss":3.1,"epss":0.0068,"slug":"cve-2019-25210-withdrawn-advisory-helm-shows-secrets-in-clear-text","title":"Withdrawn Advisory: Helm shows secrets in clear text","severity":"low","exploited":false,"published_at":"2024-03-03T21:31:25+00:00","url":"https://junglewise.ai/threats/cve-2019-25210-withdrawn-advisory-helm-shows-secrets-in-clear-text"},{"cve":"CVE-2024-25620","cvss":3.1,"epss":0.0057,"slug":"cve-2024-25620-helm-dependency-management-path-traversal","title":"GO-2024-2554 - Path traversal in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2024-02-29T17:17:45+00:00","url":"https://junglewise.ai/threats/cve-2024-25620-helm-dependency-management-path-traversal"},{"cve":"CVE-2023-25165","cvss":3.1,"epss":0.0077,"slug":"cve-2023-25165-helm-vulnerable-to-information-disclosure-via-gethostbyname","title":"GO-2023-1547 - Information disclosure in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2023-02-14T15:53:55+00:00","url":"https://junglewise.ai/threats/cve-2023-25165-helm-vulnerable-to-information-disclosure-via-gethostbyname"},{"cve":"CVE-2022-23525","cvss":3.1,"epss":0.0086,"slug":"cve-2022-23525-helm-vulnerable-to-denial-of-service-through-through-repository","title":"GO-2022-1165 - Denial of service via repository index file in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2022-12-22T23:11:46+00:00","url":"https://junglewise.ai/threats/cve-2022-23525-helm-vulnerable-to-denial-of-service-through-through-repository"},{"cve":"CVE-2022-23526","cvss":3.1,"epss":0.0086,"slug":"cve-2022-23526-helm-vulnerable-to-denial-of-service-through-schema-file","title":"GO-2022-1166 - Denial of service via schema file in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2022-12-22T22:30:45+00:00","url":"https://junglewise.ai/threats/cve-2022-23526-helm-vulnerable-to-denial-of-service-through-schema-file"},{"cve":"CVE-2022-23524","cvss":3.1,"epss":0.0078,"slug":"cve-2022-23524-helm-vulnerable-to-denial-of-service-through-string-value-parsing","title":"GO-2022-1167 - Denial of service in string value parsing in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2022-12-14T18:06:02+00:00","url":"https://junglewise.ai/threats/cve-2022-23524-helm-vulnerable-to-denial-of-service-through-string-value-parsing"},{"cve":"CVE-2021-21303","cvss":3.1,"epss":0.0103,"slug":"cve-2021-21303-improper-neutralization-of-special-elements-in-output-in-helm-sh","title":"GO-2022-1040 - Insufficient sanitization of data files in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2022-10-18T15:14:31+00:00","url":"https://junglewise.ai/threats/cve-2021-21303-improper-neutralization-of-special-elements-in-output-in-helm-sh"},{"cve":"CVE-2022-36055","cvss":3.1,"epss":0.0105,"slug":"cve-2022-36055-helm-vulnerable-to-denial-of-service-through-string-value-parsing","title":"GO-2022-0962 - Denial of service through string value parsing in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2022-09-02T15:19:52+00:00","url":"https://junglewise.ai/threats/cve-2022-36055-helm-vulnerable-to-denial-of-service-through-string-value-parsing"},{"cve":"CVE-2021-32690","cvss":3.1,"epss":0.014,"slug":"cve-2021-32690-helm-passes-repository-credentials-to-alternate-domain","title":"GO-2022-0384 - Repository credentials passed to alternate domain in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2022-07-15T23:29:45+00:00","url":"https://junglewise.ai/threats/cve-2021-32690-helm-passes-repository-credentials-to-alternate-domain"},{"cve":"CVE-2020-7919","cvss":3.1,"epss":0.0265,"slug":"cve-2020-7919-helm-uses-crypto-package-vulnerable-to-panic-from-malformed-x-509","title":"GO-2022-0229 - Panic in certificate parsing in crypto/x509 and golang.org/x/crypto/cryptobyte","severity":"low","exploited":false,"published_at":"2022-07-06T18:23:48+00:00","url":"https://junglewise.ai/threats/cve-2020-7919-helm-uses-crypto-package-vulnerable-to-panic-from-malformed-x-509"},{"cve":"CVE-2020-4053","cvss":3.1,"epss":0.0146,"slug":"cve-2020-4053-plugin-archive-directory-traversal-in-helm","title":"Plugin archive directory traversal in Helm","severity":"low","exploited":false,"published_at":"2021-06-23T18:14:36+00:00","url":"https://junglewise.ai/threats/cve-2020-4053-plugin-archive-directory-traversal-in-helm"},{"cve":"CVE-2020-11013","cvss":3.1,"epss":0.0126,"slug":"cve-2020-11013-lookup-function-information-discolosure-in-helm","title":"Lookup function information discolosure in helm","severity":"low","exploited":false,"published_at":"2021-05-27T18:44:56+00:00","url":"https://junglewise.ai/threats/cve-2020-11013-lookup-function-information-discolosure-in-helm"},{"cve":"CVE-2020-15187","cvss":3.1,"epss":0.0152,"slug":"cve-2020-15187-plugin-yaml-file-allows-for-duplicate-entries-in-helm","title":"plugin.yaml file allows for duplicate entries in helm","severity":"low","exploited":false,"published_at":"2021-05-24T16:57:21+00:00","url":"https://junglewise.ai/threats/cve-2020-15187-plugin-yaml-file-allows-for-duplicate-entries-in-helm"},{"cve":"CVE-2020-15186","cvss":3.1,"epss":0.0096,"slug":"cve-2020-15186-improper-sanitizing-of-plugin-names-in-helm","title":"Improper Sanitizing of plugin names in helm","severity":"low","exploited":false,"published_at":"2021-05-24T16:57:12+00:00","url":"https://junglewise.ai/threats/cve-2020-15186-improper-sanitizing-of-plugin-names-in-helm"},{"cve":"CVE-2020-15185","cvss":3.1,"epss":0.0088,"slug":"cve-2020-15185-repository-index-file-allows-for-duplicates-of-the-same-chart","title":"Repository index file allows for duplicates of the same chart entry in helm","severity":"low","exploited":false,"published_at":"2021-05-24T16:57:06+00:00","url":"https://junglewise.ai/threats/cve-2020-15185-repository-index-file-allows-for-duplicates-of-the-same-chart"},{"cve":"CVE-2020-15184","cvss":3.1,"epss":0.0103,"slug":"cve-2020-15184-aliases-are-never-checked-in-helm","title":"Aliases are never checked in helm","severity":"low","exploited":false,"published_at":"2021-05-24T16:56:58+00:00","url":"https://junglewise.ai/threats/cve-2020-15184-aliases-are-never-checked-in-helm"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/mattermost/mattermost-server (Go)","slug":"github-com-mattermost-mattermost-server","vulnerabilities":274,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server"},{"name":"github.com/mattermost/mattermost-server/v6 (Go)","slug":"github-com-mattermost-mattermost-server-v6","vulnerabilities":188,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6"},{"name":"github.com/mattermost/mattermost-server/v5 (Go)","slug":"github-com-mattermost-mattermost-server-v5","vulnerabilities":186,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v5"},{"name":"github.com/mattermost/mattermost/server/v8 (Go)","slug":"github-com-mattermost-mattermost-server-v8","vulnerabilities":182,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v8"},{"name":"stdlib (Go)","slug":"go-stdlib","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/go-stdlib"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"github.com/usememos/memos (Go)","slug":"github-com-usememos-memos","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-usememos-memos"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"}],"technology":{"hub":true,"name":"helm.sh/helm/v3 (Go)","slug":"helm-sh-helm-v3","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://helm.sh/","repo_url":"https://github.com/helm/helm","description":"A package manager for Kubernetes that automates the deployment and management of applications using charts.","url":"https://junglewise.ai/threats/technologies/helm-sh-helm-v3"},"most_severe":[{"cve":"CVE-2026-35206","cvss":4,"epss":0.002,"slug":"cve-2026-35206-helm-path-traversal-via-chart-yaml-name-dot-segment","title":"Helm path traversal via Chart.yaml name dot-segment","severity":"medium","exploited":false,"published_at":"2026-04-10T15:33:09+00:00","url":"https://junglewise.ai/threats/cve-2026-35206-helm-path-traversal-via-chart-yaml-name-dot-segment"},{"cve":"CVE-2020-7919","cvss":3.1,"epss":0.0265,"slug":"cve-2020-7919-helm-uses-crypto-package-vulnerable-to-panic-from-malformed-x-509","title":"GO-2022-0229 - Panic in certificate parsing in crypto/x509 and golang.org/x/crypto/cryptobyte","severity":"low","exploited":false,"published_at":"2022-07-06T18:23:48+00:00","url":"https://junglewise.ai/threats/cve-2020-7919-helm-uses-crypto-package-vulnerable-to-panic-from-malformed-x-509"},{"cve":"CVE-2020-15187","cvss":3.1,"epss":0.0152,"slug":"cve-2020-15187-plugin-yaml-file-allows-for-duplicate-entries-in-helm","title":"plugin.yaml file allows for duplicate entries in helm","severity":"low","exploited":false,"published_at":"2021-05-24T16:57:21+00:00","url":"https://junglewise.ai/threats/cve-2020-15187-plugin-yaml-file-allows-for-duplicate-entries-in-helm"},{"cve":"CVE-2020-4053","cvss":3.1,"epss":0.0146,"slug":"cve-2020-4053-plugin-archive-directory-traversal-in-helm","title":"Plugin archive directory traversal in Helm","severity":"low","exploited":false,"published_at":"2021-06-23T18:14:36+00:00","url":"https://junglewise.ai/threats/cve-2020-4053-plugin-archive-directory-traversal-in-helm"},{"cve":"CVE-2021-32690","cvss":3.1,"epss":0.014,"slug":"cve-2021-32690-helm-passes-repository-credentials-to-alternate-domain","title":"GO-2022-0384 - Repository credentials passed to alternate domain in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2022-07-15T23:29:45+00:00","url":"https://junglewise.ai/threats/cve-2021-32690-helm-passes-repository-credentials-to-alternate-domain"},{"cve":"CVE-2020-11013","cvss":3.1,"epss":0.0126,"slug":"cve-2020-11013-lookup-function-information-discolosure-in-helm","title":"Lookup function information discolosure in helm","severity":"low","exploited":false,"published_at":"2021-05-27T18:44:56+00:00","url":"https://junglewise.ai/threats/cve-2020-11013-lookup-function-information-discolosure-in-helm"},{"cve":"CVE-2022-36055","cvss":3.1,"epss":0.0105,"slug":"cve-2022-36055-helm-vulnerable-to-denial-of-service-through-string-value-parsing","title":"GO-2022-0962 - Denial of service through string value parsing in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2022-09-02T15:19:52+00:00","url":"https://junglewise.ai/threats/cve-2022-36055-helm-vulnerable-to-denial-of-service-through-string-value-parsing"},{"cve":"CVE-2021-21303","cvss":3.1,"epss":0.0103,"slug":"cve-2021-21303-improper-neutralization-of-special-elements-in-output-in-helm-sh","title":"GO-2022-1040 - Insufficient sanitization of data files in helm.sh/helm/v3","severity":"low","exploited":false,"published_at":"2022-10-18T15:14:31+00:00","url":"https://junglewise.ai/threats/cve-2021-21303-improper-neutralization-of-special-elements-in-output-in-helm-sh"},{"cve":"CVE-2020-15184","cvss":3.1,"epss":0.0103,"slug":"cve-2020-15184-aliases-are-never-checked-in-helm","title":"Aliases are never checked in helm","severity":"low","exploited":false,"published_at":"2021-05-24T16:56:58+00:00","url":"https://junglewise.ai/threats/cve-2020-15184-aliases-are-never-checked-in-helm"},{"cve":"CVE-2020-15186","cvss":3.1,"epss":0.0096,"slug":"cve-2020-15186-improper-sanitizing-of-plugin-names-in-helm","title":"Improper Sanitizing of plugin names in helm","severity":"low","exploited":false,"published_at":"2021-05-24T16:57:12+00:00","url":"https://junglewise.ai/threats/cve-2020-15186-improper-sanitizing-of-plugin-names-in-helm"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}