Directory Traversal Affecting openshift-clients-redistributable package, versions *


Severity

Recommended
0.0
medium
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.2% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL9-OPENSHIFTCLIENTSREDISTRIBUTABLE-20417486
  • published4 Oct 2026
  • disclosed28 Sept 2026

Introduced: 28 Sep 2026

NewCVE-2026-19444  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:9 openshift-clients-redistributable.

NVD Description

Note: Versions mentioned in the description apply only to the upstream openshift-clients-redistributable package and not the openshift-clients-redistributable package as distributed by RHEL. See How to fix? for RHEL:9 relevant fixed versions and status.

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows.

CVSS Base Scores

version 3.1