CVE-2026-63308

Name
CVE-2026-63308
Description
Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com https://github.com/helm/helm/commit/ba6c9a29efa7bf9198dad6a5ec12b4fb30c96017
disclosure@vulncheck.com https://github.com/helm/helm/issues/32279
disclosure@vulncheck.com https://github.com/helm/helm/pull/32290
disclosure@vulncheck.com https://www.vulncheck.com/advisories/chat2db-insecure-direct-object-reference-via-get-api-connection-datasource

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:* helm >= None <= 4.2.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
helm edge-community 3.19.0-r8 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.19.0-r7 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.19.0-r6 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.19.0-r5 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.19.0-r4 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.19.0-r3 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.19.0-r2 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.19.0-r1 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.19.0-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.18.6-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.18.4-r2 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.18.4-r1 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.18.4-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.18.3-r1 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.18.3-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.18.2-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.18.0-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.17.2-r3 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.17.2-r2 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.17.2-r1 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.17.2-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.17.1-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.17.0-r2 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.17.0-r1 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.17.0-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.16.3-r0 techknowlogick <techknowlogick@gitea.com> possibly vulnerable
helm edge-community 3.6.1-r0 None possibly vulnerable
helm edge-community 3.6.0-r0 None possibly vulnerable
helm 3.24-community 3.19.0-r7 techknowlogick <techknowlogick@gitea.com> possibly vulnerable