Dependency scanning
Check whether helm.sh/helm/v3 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2020-15184
Aliases are never checked in helm
CVE-2020-15186
Improper Sanitizing of plugin names in helm
CVE-2021-21303
Improper Neutralization of Special Elements in Output in helm.sh/helm/v3
CVE-2020-15185
Repository index file allows for duplicates of the same chart entry in helm
CVE-2021-32690
Helm passes repository credentials to alternate domain
CVE-2020-15187
plugin.yaml file allows for duplicate entries in helm
CVE-2020-4053
Plugin archive directory traversal in Helm
CVE-2026-35206
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
CVE-2020-11013
Lookup function information discolosure in helm
CVE-2023-25165
Helm vulnerable to information disclosure via getHostByName Function
CVE-2022-23524
Denial of service in string value parsing in helm.sh/helm/v3
CVE-2022-23526
Denial of service via schema file in helm.sh/helm/v3
CVE-2023-25165
Information disclosure in helm.sh/helm/v3
CVE-2025-32387
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow in helm.sh/helm
CVE-2021-32690
Repository credentials passed to alternate domain in helm.sh/helm/v3
CVE-2025-32386
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
CVE-2022-23525
Denial of service via repository index file in helm.sh/helm/v3
CVE-2025-53547
Helm vulnerable to Code Injection through malicious chart.yaml content in helm.sh/helm
CVE-2020-7919
Helm uses crypto package vulnerable to panic from malformed X.509 certificate
CVE-2025-32386
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination in helm.sh/helm
CVE-2024-26147
Helm's Missing YAML Content Leads To Panic in helm.sh/helm/v3
CVE-2025-55199
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion in helm.sh/helm
CVE-2021-32690
Duplicate Advisory: Helm passes repository credentials to alternate domain
CVE-2025-55199
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
CVE-2025-55198
Helm May Panic Due To Incorrect YAML Content
CVE-2025-53547
Helm vulnerable to Code Injection through malicious chart.yaml content
CVE-2025-32387
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
CVE-2022-36055
Denial of service through string value parsing in helm.sh/helm/v3
CVE-2024-26147
Helm's Missing YAML Content Leads To Panic
CVE-2019-25210
Withdrawn Advisory: Helm shows secrets in clear text
CVE-2022-23524
Helm vulnerable to denial of service through string value parsing
CVE-2022-36055
Helm Vulnerable to denial of service through string value parsing
CVE-2022-23526
Helm vulnerable to denial of service through schema file
CVE-2024-25620
Path traversal in helm.sh/helm/v3
CVE-2024-25620
Helm dependency management path traversal
CVE-2025-55198
Helm May Panic Due To Incorrect YAML Content in helm.sh/helm
CVE-2022-23525
Helm vulnerable to denial of service through through repository index file
CVE-2021-21303
Insufficient sanitization of data files in helm.sh/helm/v3
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes