Helm is the Kubernetes package manager and a foundational tool in container orchestration workflows, with a narrowly scoped but strategically important product footprint that includes Helm itself and the related ChartMuseum repository server. Vulnerabilities affecting the vendor reflect the complexity of package distribution and manifest handling: path-traversal flaws, resource-exhaustion conditions, injection attacks against template and configuration processing, and information-disclosure issues recur across its products and represent the attack surface inherent to a system that parses and executes untrusted chart definitions. A meaningful share of the vendor's disclosures reach serious severity, reflecting the trust boundary between chart publishers and cluster operators and the potential for container escape or cluster compromise through malicious or tampered packages. Defenders should treat Helm and ChartMuseum updates as relevant to their Kubernetes supply chain, prioritize validation of chart sources, and monitor for policy violations around chart execution and repository access; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Helm over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35204HIGH Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the p | Apr 9, 2026 | 8.6 | 31 | NO | NO |
CVE-2026-35205HIGH Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vu | Apr 9, 2026 | 7.8 | 29 | NO | NO |
CVE-2019-18658CRITICAL In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive | Nov 12, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-1010275CRITICAL helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were al | Jul 17, 2019 | 9.8 | 28 | NO | NO |
CVE-2025-53547HIGH Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execu | Jul 8, 2025 | 8.6 | 27 | NO | NO |
CVE-2021-32690HIGH Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password cre | Jun 16, 2021 | 8.6 | 27 | NO | NO |
CVE-2022-23526HIGH Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that can cause a | Dec 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-23525HIGH Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the _repo_package. The _repo_ package c | Dec 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-23524HIGH Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. | Dec 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2025-55199MEDIUM Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could cause Helm to use all available mem | Aug 14, 2025 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Helm.
Media articles that mention a CVE ID that affects a product developed by Helm — matched by CVE ID, not by vendor name.