CVE-2026-15687
Path traversal via non-tar copyDirectoryFromPod
CVSS Score
2.7
EPSS Score
0.0%
EPSS Percentile
0th
A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.
| CWE | CWE-22 |
| Vendor | kubernetes |
| Product | kubernetes-client/java |
| Ecosystems | |
| Industries | Technology |
| Published | Jul 23, 2026 |
| Last Updated | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for kubernetes kubernetes-client/java
Be the first to know when new low vulnerabilities affecting kubernetes kubernetes-client/java are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N Affected Versions
Kubernetes / kubernetes-client/java
10.0.0 < 25.0.1 26.0.0
References
Credits
๐ Ibrahim el zein and Hasan Sheet