<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:01:14 +0000</lastBuildDate>
    <item>
      <title>BIT-helm-2022-23524 — Helm vulnerable to Denial of service through string value parsing</title>
      <link>https://cve.radiocsirt.org/vuln/bit-helm-2022-23524</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: helm&lt;/p&gt;
&lt;p&gt;Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won&amp;#39;t create large arrays causing significant memory usage before passing them to the _strvals_ functions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: helm&lt;/p&gt;
&lt;p&gt;Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won&amp;#39;t create large arrays causing significant memory usage before passing them to the _strvals_ functions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-helm-2022-23524</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0781 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0781</link>
      <description>certfr-2024-avi-0781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0781</guid>
    </item>
    <item>
      <title>EUVD-2026-231887</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-231887</link>
      <description>EUVD-2026-231887</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-231887</guid>
    </item>
    <item>
      <title>fkie_cve-2022-23524</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23524</link>
      <description>&lt;p&gt;Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won&amp;#39;t create large arrays causing significant memory usage before passing them to the _strvals_ functions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, resulting in Denial of Service. Input to functions in the _strvals_ package can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics. This issue has been patched in 3.10.3. SDK users can validate strings supplied by users won&amp;#39;t create large arrays causing significant memory usage before passing them to the _strvals_ functions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-23524</guid>
    </item>
    <item>
      <title>GHSA-6rx9-889q-vv2r — Helm vulnerable to denial of service through string value parsing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6rx9-889q-vv2r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: helm.sh/helm/v3&lt;/p&gt;
&lt;p&gt;Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the _strvals_ package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The _strvals_ package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like `--set`, `--set-string`, and others that enable the user to pass in strings that are merged into the values. The _strvals_ package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing a stack overflow.&lt;/p&gt;
&lt;p&gt;Applications that use the _strvals_ package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from.&lt;/p&gt;
&lt;p&gt;The Helm Client will panic with input to `--set`, `--set-string`, and other value setting flags that causes a stack overflow. Helm is not a long running service so the panic will not affect future uses of the Helm client.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been resolved in 3.10.3.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;SDK users can validate strings supplied by users won&amp;#39;t create large arrays causing significant memory usage before passing them to the _strvals_ functions.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;Helm&amp;#39;s security policy is spelled out in detail in our [SECURIT…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: helm.sh/helm/v3&lt;/p&gt;
&lt;p&gt;Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the _strvals_ package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The _strvals_ package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like `--set`, `--set-string`, and others that enable the user to pass in strings that are merged into the values. The _strvals_ package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing a stack overflow.&lt;/p&gt;
&lt;p&gt;Applications that use the _strvals_ package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from.&lt;/p&gt;
&lt;p&gt;The Helm Client will panic with input to `--set`, `--set-string`, and other value setting flags that causes a stack overflow. Helm is not a long running service so the panic will not affect future uses of the Helm client.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been resolved in 3.10.3.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;SDK users can validate strings supplied by users won&amp;#39;t create large arrays causing significant memory usage before passing them to the _strvals_ functions.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;Helm&amp;#39;s security policy is spelled out in detail in our [SECURIT…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6rx9-889q-vv2r</guid>
    </item>
    <item>
      <title>gsd-2022-23524</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-23524</link>
      <description>gsd-2022-23524</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-23524</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-23524 — Helm vulnerable to Denial of service through string value parsing</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-23524</link>
      <description>msrc_CVE-2022-23524</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-23524</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12572-1 — helm-3.10.3-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12572-1</link>
      <description>&lt;p&gt;helm-3.10.3-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;helm-3.10.3-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12572-1</guid>
    </item>
    <item>
      <title>RHEA-2023:2102 — Red Hat Enhancement Advisory: ACS 4.0 enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhea-2023:2102</link>
      <description>&lt;p&gt;helm: Denial of service through string value parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;helm: Denial of service through string value parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhea-2023:2102</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0912 — Red Hat OpenShift: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0912</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0912</guid>
    </item>
  </channel>
</rss>
