Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j2g6-362q-6qc6 | Velero vulnerable to file path traversal when extracting from backup's tarball |
Fri, 28 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Velero-io
Velero-io velero |
|
| Vendors & Products |
Velero-io
Velero-io velero |
Tue, 25 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that escape the extraction directory during restore and overwrite sensitive files in the Velero pod filesystem. This issue is fixed in version 1.18.1. | |
| Title | Velero vulnerable to file path traversal when extracting from backup's tarball | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-28T22:38:21.971Z
Reserved: 2026-03-12T15:29:36.559Z
Link: CVE-2026-32637
Updated: 2026-08-28T22:38:17.901Z
Status : Received
Published: 2026-08-25T22:17:02.380
Modified: 2026-08-28T23:17:06.490
Link: CVE-2026-32637
No data.
OpenCVE Enrichment
Updated: 2026-08-28T20:34:23Z
Github GHSA