MEDIUM
velero-io
CVE published 2026-08-25
CVE-2026-32637
A vulnerability in Velero, a tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes, allows an attacker who compromises the backup object-storage backend to upload a malicious backup tarball. This tarball can contain parent-directory paths that escape the extraction directory during restore, potentially overwriting sensitive files in the Velero pod filesystem. Th [truncated]