{"id":"AZL-92991","summary":"CVE-2026-63308 affecting package cert-manager for versions less than 1.12.15-11","details":"Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can include empty files in Helm charts to cause deterministic render failures across template, install, upgrade, lint, and SDK Engine.Render operations.","modified":"2026-08-31T05:26:27Z","published":"2026-07-17T17:17:17Z","upstream":["CVE-2026-63308"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63308"}],"affected":[{"package":{"name":"cert-manager","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/cert-manager"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.15-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92991.json"}}],"schema_version":"1.9.0"}