Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Prior to upgrading, this vulnerability can be mitigated by ensuring you only copy files from trusted pods, or by ensuring tar is available in the container to use the secure tar-based copy path.
| Link | Providers |
|---|---|
| https://github.com/kubernetes-client/java/issues/4861 |
|
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false. | |
| Title | Path traversal via non-tar copyDirectoryFromPod | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2026-07-23T19:03:12.469Z
Reserved: 2026-07-13T23:31:31.228Z
Link: CVE-2026-15687
Updated: 2026-07-23T19:03:09.190Z
No data.
No data.
OpenCVE Enrichment
No data.