CVE-2026-32637
Impact
_What kind of vulnerability is it? Who is impacted?_
If the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following:
- ../../../tmp/escape_1 -> file created at /tmp/escape_1
- ../../../../../../../../tmp/escape_2 -> file created at /tmp/escape_2
- ../../../tmp/cron_poc -> would be /etc/cron.d/backdoor in real attack
- ../../../tmp/ssh_poc -> would be ~/.ssh/authorized_keys
- ../../../tmp/kubeconfig_poc -> would be ~/.kube/config
It's possible that extracting files from the tarball during restore can overwrite sensitive files in the Velero pod filesystem.
Patches
_Has the problem been patched? What versions should users upgrade to?_
By far, there is no patch yet.
We are working on the main branch, then cherry-pick to the release-1.18 for v1.18.1 patch.
Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
There is no workaround, but the good news is that keeping your OSS safe will prevent the vulnerability.
⚡ Watch CVE-2026-32637
Get an email if CVE-2026-32637 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-32637)