Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/helm/helm(Go) | 2.0.0 | 2.16.8 | N/A |
| helm.sh/helm/v3(Go) | 3.0.0 | 3.1.0 | N/A |
| golang.org/x/crypto(Go) | 0 | 0.0.0-20200124225646-8b5121be2f68 | N/A |
CVSS Metrics