Directory Traversal Vulnerability in Velero for Kubernetes
CVE-2026-32637
5.9MEDIUM
What is CVE-2026-32637?
Velero, the open source tool designed for backing up and restoring Kubernetes cluster resources, presents a vulnerability that allows an attacker with access to the backup object-storage backend to upload a malicious backup tarball. This tarball can leverage parent-directory paths to escape the designated extraction directory, resulting in the potential overwriting of sensitive files within the Velero pod filesystem. This issue was resolved in version 1.18.1, reinforcing the security of backup operations within Kubernetes environments.
Affected Version(s)
velero < 1.18.1
