Helm
Products
13- 31 CVEs
- 16 CVEs
- 16 CVEs
- 5 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
55| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32968 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2026 | Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383. | ||
| CVE-2024-45275 | Cri | 0.64 | 9.8 | 0.01 | Oct 15, 2024 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. | ||
| CVE-2024-45274 | Cri | 0.64 | 9.8 | 0.02 | Oct 15, 2024 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. | ||
| CVE-2019-18658 | Cri | 0.64 | 9.8 | 0.02 | Nov 12, 2019 | In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a special file such as… | ||
| CVE-2023-0985 | Hig | 0.57 | 8.8 | 0.01 | Jun 6, 2023 | An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to… | ||
| CVE-2019-1010275 | Cri | 0.57 | 9.8 | 0.01 | Jul 17, 2019 | helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were aloowed. The component is: helm (many files updated, see https://github.com/helm/helm/pull/3152/files/… | ||
| CVE-2024-45273 | Hig | 0.55 | 8.4 | 0.00 | Oct 15, 2024 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. | ||
| CVE-2024-45271 | Hig | 0.55 | 8.4 | 0.00 | Oct 15, 2024 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. | ||
| CVE-2022-36049 | Hig | 0.50 | 7.7 | 0.01 | Sep 7, 2022 | Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is tightly integrated with the Helm SDK. A vulnerability found… | ||
| CVE-2026-35204 | Hig | 0.49 | 8.6 | 0.00 | Apr 9, 2026 | Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the… | ||
| CVE-2026-32969 | Hig | 0.49 | 7.5 | 0.00 | Mar 23, 2026 | An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality. | ||
| CVE-2024-45276 | Hig | 0.49 | 7.5 | 0.01 | Oct 15, 2024 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. | ||
| CVE-2024-45272 | Hig | 0.49 | 7.5 | 0.01 | Oct 15, 2024 | An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost. | ||
| CVE-2020-35558 | Hig | 0.49 | 7.5 | 0.01 | Feb 16, 2021 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials. | ||
| CVE-2025-53547 | Hig | 0.48 | 8.5 | 0.00 | Jul 8, 2025 | Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a… | ||
| CVE-2026-35205 | Hig | 0.44 | 7.8 | 0.00 | Apr 9, 2026 | Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4. | ||
| CVE-2019-25210 | Med | 0.42 | 6.5 | 0.01 | Mar 3, 2024 | An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that… | ||
| CVE-2024-26147 | Hig | 0.42 | 7.5 | 0.01 | Feb 21, 2024 | Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all… | ||
| CVE-2020-12527 | Med | 0.42 | 6.5 | 0.01 | Mar 2, 2021 | An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding… | ||
| CVE-2020-35557 | Med | 0.42 | 6.5 | 0.01 | Feb 16, 2021 | An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation. |
- risk 0.64cvss 9.8epss 0.01
Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.
- risk 0.64cvss 9.8epss 0.01
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
- risk 0.64cvss 9.8epss 0.02
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
- risk 0.64cvss 9.8epss 0.02
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a special file such as…
- risk 0.57cvss 8.8epss 0.01
An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to…
- risk 0.57cvss 9.8epss 0.01
helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were aloowed. The component is: helm (many files updated, see https://github.com/helm/helm/pull/3152/files/…
- risk 0.55cvss 8.4epss 0.00
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
- risk 0.55cvss 8.4epss 0.00
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
- risk 0.50cvss 7.7epss 0.01
Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is tightly integrated with the Helm SDK. A vulnerability found…
- risk 0.49cvss 8.6epss 0.00
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the…
- risk 0.49cvss 7.5epss 0.00
An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.
- risk 0.48cvss 8.5epss 0.00
Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a…
- risk 0.44cvss 7.8epss 0.00
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that…
- risk 0.42cvss 7.5epss 0.01
Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding…
- risk 0.42cvss 6.5epss 0.01
An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.