PatchSiren

velero-io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM velero-io CVE published 2026-08-25

CVE-2026-32637

A vulnerability in Velero, a tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes, allows an attacker who compromises the backup object-storage backend to upload a malicious backup tarball. This tarball can contain parent-directory paths that escape the extraction directory during restore, potentially overwriting sensitive files in the Velero pod filesystem. Th [truncated]