GO-2022-1165

    Dashboard / Vulnerabilities / GO-2022-1165

    GO-2022-1165

    Published: 22 Dec 2022Last Modified: 4 Feb 2026

    Summary: Denial of service via repository index file in helm.sh/helm/v3

    Details: Applications that use the repo package in the Helm SDK to parse an index file can suffer a Denial of Service when that input causes a panic that cannot be recovered from. The repo package contains a handler that processes the index file of a repository. For example, the Helm client adds references to chart repositories where charts are managed. The repo package parses the index file of the repository and loads it into memory. Some index files can cause array data structures to be created causing a memory violation. The Helm Client will panic with an index file that causes a memory violation panic. Helm is not a long running service so the panic will not affect future uses of the Helm client.

    Affected packages

    Package

    Name: helm.sh/helm/v3

    Purl: pkg:golang/helm.sh/helm/v3

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.10.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2022-1165 | CVE-DB