#32219·Helm

Potential Vulnerability

Author: laurie-tyzCreated Jun 15, 2026Updated Sep 14, 2026
LabelsStale

What happened?

The CERT Coordination Center has a multi-vendor/developer case regarding a vulnerability which may affect this library. We request that a security representative respond to the [email protected] address and request an account be approved for anyone responsible for security or maintenance of the project.

Information for vendors can be found here: https://certcc.github.io/VINCE-docs/For-Vendors/

What did you expect to happen?

CERT Coordination Center asks that a representative join our vulnerability handling platform. Once on the platform, Helm/helm will be provided with a set of files specific to helm. As this is a public bug report, we will refrain from posting any files.

Best, CERT Coordination Center

How can we reproduce it (as minimally and precisely as possible)?

As this is a public bug report form, the CERT/CC will refrain from posting any files.

Helm version

helm ≤ v3.16.3

Kubernetes version

unknown