Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38507
HistoryDec 16, 2022 - 3:20 a.m.

Denial Of Service (DoS)

2022-12-1603:20:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
helm
vulnerability
dos
parser
software security

0.001 Low

EPSS

Percentile

36.7%

helm.sh/helm/v3 is vulnerable to denial of service. The vulnerability exists because the parser.go does not properly implement the maximum level of nesting for a value name, allowing an attacker to cause an application crash through stack overflow by passing a malicious string.