CVE-2025-32387
MediumAdvisory
Published 9 Apr 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.005
- 40th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 154
- of 17,781 indexed, latest versions
- Container images
- 157
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
Carried by container images the latest versions of 154 of 17,781 indexed charts deploy, on 157 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| helm.sh/ | v0.0.0-20221012195806-9f88ccb6aee4, v0.0.0-20221214143859-835b7334cfe2, v0.0.0-20230113165805-472c5736ab01, v0.0.0-20230308205603-912ebc1cd10d+66 more | 3.17.3 | 157 |
| helmdeb | 3.18.1-1 | no fix listed | 1 |
- OSV records
- GHSA-5xqw-8hwv-wg92UBUNTU-CVE-2025-32387
- Also known as
- BIT-helm-2025-32387, GO-2025-3602
Charts affected
154 by stars
Container images carrying it
157 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 3e010e1188f1 | helm.sh/ | 3.17.3 | 1 |
| quay.io/ | 0bbe8b451fa3 | helm.sh/ | 3.17.3 | 1 |
| quay.io/ | 6ba82beff18e | helm.sh/ | 3.17.3 | 1 |
| quay.io/ | 5b62aaade3c9 | helm.sh/ | 3.17.3 | 1 |
| quay.io/ | 9a6c84560d44 | helm.sh/ | 3.17.3 | 1 |
| registry.gitlab.com/ | 80ef8ceffc92 | helm.sh/ | 3.17.3 | 1 |
| registry.gitlab.com/ | 36b19b72120e | helm.sh/ | 3.17.3 | 1 |