K8s Security: [Security Advisory] CVE-2026-3864: CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server
Open
external
kubernetes
on-call
security
- Dominant language
- Shell
- Stars
- 1.5k
- Forks
- 198
- Avg merge
- 10h 46m
- Merged PRs (30d)
- 28
Description
Go to [the Kubernetes group](https://groups.google.com/g/kubernetes-security-announce) to view the announcement.
Follow the on-call runbook to backport fixes to all supported versions.
Contributor guide
Research direction
The issue points to the Kubernetes security-announce group and an on-call runbook, but names no repository files or tests. Start by reading the announcement and runbook to identify the supported versions and required backports. Done means the security fix has been backported across all supported versions.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- kubernetes
- Domain
- infrastructure, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100