aws / aws/eks-distro

K8s Security: [Security Advisory] CVE-2026-3864: CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server

Open
#4,582 0 comments 0 reactions 0 assignees View on GitHub
external kubernetes on-call security
Dominant language
Shell
Stars
1.5k
Forks
198
Avg merge
10h 46m
Merged PRs (30d)
28

Description

Go to [the Kubernetes group](https://groups.google.com/g/kubernetes-security-announce) to view the announcement.

Follow the on-call runbook to backport fixes to all supported versions.

Contributor guide

Open the contributing guide

Research direction

The issue points to the Kubernetes security-announce group and an on-call runbook, but names no repository files or tests. Start by reading the announcement and runbook to identify the supported versions and required backports. Done means the security fix has been backported across all supported versions.

Written by the indexing model from the issue text.

Assessment

Tech stack
kubernetes
Domain
infrastructure, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.