Feed/CVE-2026-32637
CVE-2026-32637MEDIUMCVSS 0.0

Velero vulnerable to file path traversal when extracting from backup's tarball

Published Aug 20, 2026·Updated Aug 20, 2026

NVD Description

### Impact _What kind of vulnerability is it? Who is impacted?_ If the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following: * ../../../tmp/escape_1 -> file created at /tmp/escape_1 * ../../../../../../../../tmp/escape_2 -> file created at /tmp/escape_2 * ../../../tmp/cron_poc -> would be /etc/cron.d/backdoor in real attack * ../../../tmp/ssh_poc -> would be ~/.ssh/authorized_keys * ../../../tmp/kubeconfig_poc -> would be ~/.kube/config It's possible that extracting files from the tarball during restore can overwrite sensitive files in the Velero pod filesystem. ### Patches _Has the problem been patched? What versions should users upgrade to?_ By far, there is no patch yet. We are working on the main branch, then cherry-pick to the release-1.18 for v1.18.1 patch. ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ There is no workaround, but the good news is that keeping your OSS safe will prevent the vulnerability.

Affected Packages (1)

github.com/vmware-tanzu/veleroGO
Fixed in 1.18.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free