Improper Validation of Array Index Affecting helm-4 package, versions <4.2.4-r0


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.28% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-HELM4-18767195
  • published14 Aug 2026
  • disclosed17 Jul 2026

Introduced: 17 Jul 2026

CVE-2026-63308  (opens in a new tab)
CWE-129  (opens in a new tab)

How to fix?

Upgrade Chainguard helm-4 to version 4.2.4-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream helm-4 package and not the helm-4 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations.

CVSS Base Scores

version 3.1