{"schema_version":"1.7.3","id":"GHSA-6rx9-889q-vv2r","published":"2022-12-14T21:36:56Z","modified":"2026-02-04T02:56:09.339332Z","aliases":["BIT-helm-2022-23524","CVE-2022-23524","GO-2022-1167"],"related":["CGA-jc44-82v5-wpj7"],"summary":"Helm vulnerable to denial of service through string value parsing","details":"Fuzz testing, by Ada Logics and sponsored by the CNCF, identified input to functions in the _strvals_ package that can cause a stack overflow. In Go, a stack overflow cannot be recovered from. Applications that use functions from the _strvals_ package in the Helm SDK can have a Denial of Service attack when they use this package and it panics.\n\n### Impact\n\nThe _strvals_ package contains a parser that turns strings into Go structures. For example, the Helm client has command line flags like `--set`, `--set-string`, and others that enable the user to pass in strings that are merged into the values. The _strvals_ package converts these strings into structures Go can work with. Some string inputs can cause array data structures to be created causing a stack overflow.\n\nApplications that use the _strvals_ package in the Helm SDK to parse user supplied input can suffer a Denial of Service when that input causes a panic that cannot be recovered from.\n\nThe Helm Client will panic with input to `--set`, `--set-string`, and other value setting flags that causes a stack overflow. Helm is not a long running service so the panic will not affect future uses of the Helm client.\n\n### Patches\n\nThis issue has been resolved in 3.10.3. \n\n### Workarounds\n\nSDK users can validate strings supplied by users won't create large arrays causing significant memory usage before passing them to the _strvals_ functions.\n\n### For more information\n\nHelm's security policy is spelled out in detail in our [SECURITY](https://github.com/helm/community/blob/master/SECURITY.md) document.\n\n### Credits\n\nDisclosed by Ada Logics in a fuzzing audit sponsored by CNCF.","affected":[{"package":{"name":"helm.sh/helm/v3","ecosystem":"Go","purl":"pkg:golang/helm.sh/helm/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.10.3"}]}],"database_specific":{"last_known_affected_version_range":"<= 3.10.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-6rx9-889q-vv2r/GHSA-6rx9-889q-vv2r.json"}}],"references":[{"type":"WEB","url":"https://github.com/helm/helm/security/advisories/GHSA-6rx9-889q-vv2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23524"},{"type":"WEB","url":"https://github.com/helm/helm/commit/3636f6824757ff734cb265b8770efe48c1fb3737"},{"type":"PACKAGE","url":"https://github.com/helm/helm"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2022-1167"}],"database_specific":{"cwe_ids":["CWE-400"],"github_reviewed":true,"github_reviewed_at":"2022-12-14T21:36:56Z","nvd_published_at":"2022-12-15T19:15:00Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}