CVE-2026-32637EPSS p43.7%
CVE-2026-32637CVE-2026-32637
Description
Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that escape the extraction directory during restore and overwrite sensitive files in the Velero pod filesystem. This issue is fixed in version 1.18.1.
Scoring
| EPSS | 0.54% probability of exploitation · percentile 43.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-09 |