THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-32637 — Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that

[NVD] CVE-2026-32637 — Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that

mednvdPublished 2026-08-25

CVE-2026-32637 CVSS: None Published: 2026-08-25T22:17:02.380

Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that escape the extraction directory during restore and overwr

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-32637