Microsoft Security Response Center guidance
Vendor revision: Sep 6, 2026CBL-Mariner Releases
Vendor-listed releases
- 1.12.15-4
- 3.14.2-6
- 3.15.2-3
Vulnerability intelligence
CVE-2025-32387 and is rated Medium severity with a CVSS score of 6.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
Vendor-listed releases
Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow.
This issue has been resolved in Helm v3.17.3.
Source: NVD