The Helm project has a common process and policy that can be found here.
Security: helm/helm
Security
SECURITY.md
-
Path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directoryGHSA-vmx8-mqv2-9gmg published
Apr 9, 2026 by gjenkins8High -
Plugin verification fails open when `.prov` is missing, allowing unsigned plugin installGHSA-q5jf-9vfq-h4h7 published
Apr 9, 2026 by gjenkins8Critical -
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segmentGHSA-hr2v-4r36-88hr published
Apr 9, 2026 by gjenkins8Moderate -
Incorrect YAML Content Leads To PanicGHSA-f9f8-9pmf-xv68 published
Aug 13, 2025 by robertsircModerate -
Helm Charts with Specific JSON Schema Values Can Cause Memory ExhaustionGHSA-9h84-qmv7-982p published
Aug 13, 2025 by robertsircModerate -
Chart Dependency Updating With Malicious Chart.yaml Content And SymlinkGHSA-557j-xg8c-q2mm published
Jul 8, 2025 by robertsircHigh -
Specially Crafted JSON Schema Can Cause Stack OverflowGHSA-5xqw-8hwv-wg92 published
Apr 9, 2025 by robertsircModerate -
Specially Crafted Chart Archive Can Cause Out Of Memory TerminationGHSA-4hfp-h4cw-hj8p published
Apr 9, 2025 by robertsircModerate -
Missing YAML Content Leads To PanicGHSA-r53h-jv2g-vpx6 published
Feb 21, 2024 by mattfarinaModerate -
Dependency management path traversalGHSA-v53g-5gjp-272r published
Feb 14, 2024 by mattfarinaModerate
Learn more about advisories related to helm/helm in the GitHub Advisory Database