CVE-2026-63308: Helm
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations.
Affected products
- Helm Helm: up to and including 4.2.3
Published 2026-07-17. Last modified 2026-07-30.