CVE-2026-63308: Helm

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations.

Affected products

  • Helm Helm: up to and including 4.2.3

Published 2026-07-17. Last modified 2026-07-30.