Helm corrected CVE-2024-25620, which lets a chart with relative-path components in its Chart.yaml name write files outside the intended dependency directory, and CVE-2024-26147, in which metadata-free malformed index.yaml or plugin.yaml files can trigger a panic. The latter can be exploited through repository processing or a malicious installed plugin; because Helm enumerates known plugins at startup, it can cause every Helm invocation to fail. The issues affect both the Helm CLI and SDK users; fixes are available in Helm 3.14.1 for the path traversal flaw and 3.14.2 for the panic condition.
Red Hat shipped remediations through updates including Advanced Cluster Management for Kubernetes 2.9.3 and OpenShift GitOps 1.12.4, with related advisories covering affected OpenShift Container Platform and Advanced Cluster Security releases. Organizations should upgrade to a fixed Helm release or applicable Red Hat container updates, inspect charts and dependencies for relative-path manipulation in Chart.yaml names, and remove untrusted or malicious plugins; SDK consumers that cannot immediately upgrade should recover safely from panics around affected repository and plugin-processing calls.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:6236, a Moderate-severity security and bug-fix advisory for Advanced Cluster Management for Kubernetes 2.10.5 on RHEL 9 x86_64. The update provides container images that address OpenTelemetry denial-of-service flaws CVE-2023-45142 and CVE-2023-47108, among other listed CVEs.
Red Hat published RHSA-2024:4626, a Moderate-severity update for OpenShift GitOps 1.11.6. It remediated CVE-2024-24786, CVE-2024-26147, and CVE-2024-25620 in the Argo CD container, along with multiple vulnerabilities in the Redis container.
Red Hat published RHSA-2024:4163 for OpenShift GitOps v1.12.4. The Moderate-severity update remediated the two Helm vulnerabilities as well as CVE-2024-24786, an invalid-JSON infinite-loop denial-of-service flaw in golang-protobuf.
Red Hat published RHSA-2024:1549, a Critical advisory for Advanced Cluster Security for Kubernetes 4.3, delivering RHACS 4.3.6 images. The update remediates go-git path traversal/RCE flaw CVE-2023-49569 and Helm flaws CVE-2024-26147 and CVE-2019-25210, and fixes a Jira-notifier crash-loop defect.
Red Hat published RHSA-2024:1328 for Advanced Cluster Management for Kubernetes 2.9.3. The Moderate-severity update remediated CVE-2024-25620 and CVE-2024-26147, along with two OpenTelemetry denial-of-service flaws.
Helm resolved CVE-2024-26147 in version 3.14.2. Malformed index.yaml or plugin.yaml files lacking expected metadata could trigger a panic, including on every client invocation when caused by a known malicious plugin.
Helm resolved CVE-2024-25620 in version 3.14.1. A chart name containing relative-path components in Chart.yaml could cause a chart to be saved outside its intended directory through the Helm client or SDK.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.