Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Prior to upgrading, this vulnerability can be mitigated by ensuring you only copy files from trusted pods, or by ensuring tar is available in the container to use the secure tar-based copy path.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/kubernetes-client/java/issues/4861 |
|
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false. | |
| Title | Path traversal via non-tar copyDirectoryFromPod | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2026-07-23T19:03:12.469Z
Reserved: 2026-07-13T23:31:31.228Z
Link: CVE-2026-15687
Updated: 2026-07-23T19:03:09.190Z
No data.
No data.
OpenCVE Enrichment
No data.