Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92991.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92991
Upstream
Published
2026-07-17T17:17:17Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-63308 affecting package cert-manager for versions less than 1.12.15-11
Details

Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations.

References

Affected packages

Azure Linux:3 / cert-manager

Package

Name
cert-manager
Purl
pkg:rpm/azure-linux/cert-manager

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.15-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92991.json"