<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:49:50.652126+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-helm-2022-23524</id>
    <title>BIT-helm-2022-23524 — Helm vulnerable to Denial of service through string value parsing</title>
    <updated>2026-10-03T23:49:50.790325+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: helm</p>
<p>Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the _strvals_ functions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-helm-2022-23524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0781</id>
    <title>certfr-2024-avi-0781 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
    <updated>2026-10-03T23:49:50.790391+00:00</updated>
    <content>certfr-2024-avi-0781</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-231887</id>
    <title>EUVD-2026-231887</title>
    <updated>2026-10-03T23:49:50.790412+00:00</updated>
    <content>EUVD-2026-231887</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-231887"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23524</id>
    <title>fkie_cve-2022-23524</title>
    <updated>2026-10-03T23:49:50.790425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the _strvals_ functions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-23524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6rx9-889q-vv2r</id>
    <title>GHSA-6rx9-889q-vv2r — Helm vulnerable to denial of service through string value parsing</title>
    <updated>2026-10-03T23:49:50.790452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: helm.sh/helm/v3</p>
<p>Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the _strvals_ package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics.</p>
<p>### Impact</p>
<p>The _strvals_ package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like `--set`, `--set-string`, and others that enable the user to pass in strings that are merged into the values. The _strvals_ package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing a stack overflow.</p>
<p>Applications that use the _strvals_ package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from.</p>
<p>The Helm Client will panic with input to `--set`, `--set-string`, and other value setting flags that causes a stack overflow. Helm is not a long running service so the panic will not affect future uses of the Helm client.</p>
<p>### Patches</p>
<p>This issue has been resolved in 3.10.3.</p>
<p>### Workarounds</p>
<p>SDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the _strvals_ functions.</p>
<p>### For more information</p>
<p>Helm's security policy is spelled out in detail in our [SECURIT…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6rx9-889q-vv2r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-23524</id>
    <title>gsd-2022-23524</title>
    <updated>2026-10-03T23:49:50.790494+00:00</updated>
    <content>gsd-2022-23524</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-23524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-23524</id>
    <title>msrc_CVE-2022-23524 — Helm vulnerable to Denial of service through string value parsing</title>
    <updated>2026-10-03T23:49:50.790507+00:00</updated>
    <content>msrc_CVE-2022-23524</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-23524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12572-1</id>
    <title>openSUSE-SU-2024:12572-1 — helm-3.10.3-2.1 on GA media</title>
    <updated>2026-10-03T23:49:50.790523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>helm-3.10.3-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12572-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2023:2102</id>
    <title>RHEA-2023:2102 — Red Hat Enhancement Advisory: ACS 4.0 enhancement update</title>
    <updated>2026-10-03T23:49:50.790540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>helm: Denial of service through string value parsing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2023:2102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0912</id>
    <title>WID-SEC-W-2023-0912 — Red Hat OpenShift: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T23:49:50.790556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0912"/>
  </entry>
</feed>
