GHSA-cjjc-xp8v-855w

    Dashboard / Vulnerabilities / GHSA-cjjc-xp8v-855w

    GHSA-cjjc-xp8v-855w

    Published: 23 Jun 2021Last Modified: 10 Sept 2026

    Summary: Helm uses crypto package vulnerable to panic from malformed X.509 certificate

    Details: The Helm core maintainers have identified a high severity security vulnerability in Go's `crypto` package affecting all versions prior to Helm 2.16.8 and Helm 3.1.0. Thanks to @ravin9249 for identifying the vulnerability. ### Impact Go before 1.12.16 and 1.13.x before 1.13.7 (and the `crypto/cryptobyte` package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients resulting in a panic via a malformed X.509 certificate. This may allow a remote attacker to cause a denial of service. ### Patches A patch to compile Helm against Go 1.14.4 has been provided for Helm 2 and is available in Helm 2.16.8. Helm 3.1.0 and newer are compiled against Go 1.13.7+. ### Workarounds No workaround is available. Users are urged to upgrade. ### References - https://nvd.nist.gov/vuln/detail/CVE-2020-7919 - https://github.com/helm/helm/pull/8288 ### For more information If you have any questions or comments about this advisory: * Open an issue in [the Helm repository](https://github.com/helm/helm/issues) * For security-specific issues, email us at <[email protected]>

    Affected packages

    Package

    Name: github.com/helm/helm

    Purl: pkg:golang/github.com/helm/helm

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 2.0.0
    Fixed -2.16.8

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-cjjc-xp8v-855w | CVE-DB