Directory Traversal Vulnerability in Velero for Kubernetes
CVE-2026-32637

5.9MEDIUM

Key Information:

Vendor

Velero-io

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-32637?

Velero, the open source tool designed for backing up and restoring Kubernetes cluster resources, presents a vulnerability that allows an attacker with access to the backup object-storage backend to upload a malicious backup tarball. This tarball can leverage parent-directory paths to escape the designated extraction directory, resulting in the potential overwriting of sensitive files within the Velero pod filesystem. This issue was resolved in version 1.18.1, reinforcing the security of backup operations within Kubernetes environments.

Affected Version(s)

velero < 1.18.1

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.