{"id":"CVE-2026-32637","aliases":["GHSA-j2g6-362q-6qc6","GO-2026-6259"],"url":"https://o3.security/vulnerability/CVE-2026-32637","summary":"Velero vulnerable to file path traversal when extracting from backup's tarball","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\nIf the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following:\n* ../../../tmp/escape_1              -> file created at /tmp/escape_1\n* ../../../../../../../../tmp/escape_2 -> file created at /tmp/escape_2\n* ../../../tmp/cron_poc              -> would be /etc/cron.d/backdoor in real attack\n* ../../../tmp/ssh_poc               -> would be ~/.ssh/authorized_keys\n* ../../../tmp/kubeconfig_poc        -> would be ~/.kube/config\n\nIt's possible that extracting files from the tarball during restore can overwrite sensitive files in the Velero pod filesystem. \n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nBy far, there is no patch yet.\nWe are working on the main branch, then cherry-pick to the release-1.18 for v1.18.1 patch.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nThere is no workaround, but the good news is that keeping your OSS safe will prevent the vulnerability.","published":"2026-08-25T21:15:31.881Z","modified":"2026-09-29T18:26:48.603280949Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/vmware-tanzu/velero","fixedVersion":"1.18.1"}],"fix":{"url":"https://github.com/velero-io/velero/commit/3f8e3588496391979915ace065f732a9013c1cf0","label":"velero-io/velero@3f8e358"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32637.json"},{"type":"ADVISORY","url":"https://github.com/velero-io/velero/security/advisories/GHSA-j2g6-362q-6qc6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32637"},{"type":"REPORT","url":"https://github.com/securego/gosec/issues/324"},{"type":"FIX","url":"https://github.com/velero-io/velero/commit/3f8e3588496391979915ace065f732a9013c1cf0"},{"type":"FIX","url":"https://github.com/velero-io/velero/commit/c7fa4bfe3571667e9731f3f504da3c6be709a24c"},{"type":"PACKAGE","url":"https://github.com/velero-io/velero"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-29T18:26:48.603280949Z"}}