Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-36049 Details

Description

Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage Helm chart releases. Helm controller is tightly integrated with the Helm SDK. A vulnerability found in the Helm SDK that affects flux2 v0.0.17 until v0.32.0 and helm-controller v0.0.4 until v0.23.0 allows for specific data inputs to cause high memory consumption. In some platforms, this could cause the controller to panic and stop processing reconciliations. In a shared cluster multi-tenancy environment, a tenant could create a HelmRelease that makes the controller panic, denying all other tenants from their Helm releases being reconciled. Patches are available in flux2 v0.32.0 and helm-controller v0.23.0.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-770Allocation of Resources Without Limits or Throttling[email protected]
CWE-400Uncontrolled Resource Consumption[email protected]

Affected Products

ProductVersions
helm helm
>= 3.0.0, < 3.9.4

CPE

  • cpe:2.3:a:helm:helm:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fluxcd flux2
>= 0.0.17, < 0.32.0

CPE

  • cpe:2.3:a:fluxcd:flux2:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fluxcd helm-controller
>= 0.0.4, < 0.23.0

CPE

  • cpe:2.3:a:fluxcd:helm-controller:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-36049
NVD Published Date:
Sep 7, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-36049 Details - Not Deferred