StackRadar

CVE-2025-32386

Medium

Advisory

Published 9 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
159
of 17,787 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 2
affected packages

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

Carried by container images the latest versions of 159 of 17,787 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
helm.sh/helm/v3golangv0.0.0-20221012195806-9f88ccb6aee4, v0.0.0-20221214143859-835b7334cfe2, v0.0.0-20230113165805-472c5736ab01, v0.0.0-20230308205603-912ebc1cd10d+67 more3.17.3160
helmdeb3.18.1-1no fix listed1
OSV records
GHSA-4hfp-h4cw-hj8pUBUNTU-CVE-2025-32386
Also known as
BIT-helm-2025-32386, GO-2025-3601

Charts affected

159 by stars
ChartLatestAffected imagesRadar Score
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2025-32386.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
helm.sh/helm/v3@v3.12.3
3.17.3
quay.io/devtron/kubectl:latest2ad610626658
helm.sh/helm/v3@v0.0.0-20221012195806-9f88ccb6aee4
3.17.3

Open the chart page →

66,542
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-32386.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
helm.sh/helm/v3@v0.0.0-20221012195806-9f88ccb6aee4
3.17.3

Open the chart page →

31,447
harborsb-helm-charts0.3.01 of 2See more

harbor sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-32386.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.11.1c017dd84ee96
helm.sh/helm/v3@v3.14.4
3.17.3

Open the chart page →

1,680
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2025-32386.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
helm.sh/helm/v3@v3.11.3
3.17.3
goharbor/harbor-jobservice:v2.9.039435daedd0c
helm.sh/helm/v3@v3.11.3
3.17.3
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
helm.sh/helm/v3@v3.12.1
3.17.3

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-32386.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
helm.sh/helm/v3@v3.12.1
3.17.3

Open the chart page →

2,505
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-32386.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
helm.sh/helm/v3@v3.14.3
3.17.3

Open the chart page →

1,360
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-32386.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
helm.sh/helm/v3@v3.14.2
3.17.3

Open the chart page →

2,478
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-32386.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
helm.sh/helm/v3@v3.11.0
3.17.3

Open the chart page →

6,272
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-32386.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
helm.sh/helm/v3@v0.0.0-20230113165805-472c5736ab01
3.17.3

Open the chart page →

13,197

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
helm.sh/helm/v3@v3.12.2
3.17.3
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
helm.sh/helm/v3@v3.11.3
3.17.3
1
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
helm.sh/helm/v3@v3.14.4
3.17.3
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
helm.sh/helm/v3@v3.8.0
3.17.3
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
helm.sh/helm/v3@v3.7.1
3.17.3
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
helm.sh/helm/v3@v3.3.4
3.17.3
1
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
helm.sh/helm/v3@v3.6.3
3.17.3
1
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
helm.sh/helm/v3@v3.6.3
3.17.3
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
helm.sh/helm/v3@v0.0.0-20231012132431-3547a4b5bf5e
3.17.3
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
helm.sh/helm/v3@v3.7.0
3.17.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.