{"id":"CVE-2026-32637","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-32637","summary":"Velero vulnerable to file path traversal when extracting from backup's tarball","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\nIf the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following:\n* ../../../tmp/escape_1              -> file created at /tmp/escape_1\n* ../../../../../../../../tmp/escape_2 -> file created at /tmp/escape_2\n* ../../../tmp/cron_poc              -> would be /etc/cron.d/backdoor in real attack\n* ../../../tmp/ssh_poc               -> would be ~/.ssh/authorized_keys\n* ../../../tmp/kubeconfig_poc        -> would be ~/.kube/config\n\nIt's possible that extracting files from the tarball during restore can overwrite sensitive files in the Velero pod filesystem. \n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nBy far, there is no patch yet.\nWe are working on the main branch, then cherry-pick to the release-1.18 for v1.18.1 patch.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nThere is no workaround, but the good news is that keeping your OSS safe will prevent the vulnerability.","published":"2026-08-20T17:26:07Z","modified":"2026-08-20T17:30:08.258325176Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/vmware-tanzu/velero","fixedVersion":"1.18.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/velero-io/velero/security/advisories/GHSA-j2g6-362q-6qc6"},{"type":"WEB","url":"https://github.com/securego/gosec/issues/324"},{"type":"PACKAGE","url":"https://github.com/velero-io/velero"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T17:30:08.258325176Z"}}