aws / aws/eks-distro

K8s Security: [Security Advisory - Kubernetes Java Client] CVE-2026-15687: Path traversal via non-tar copyDirectoryFromPod

Open
#4,802 0 comments 0 reactions 0 assignees View on GitHub
external kubernetes on-call security
Dominant language
Shell
Stars
1.5k
Forks
198
Avg merge
10h 46m
Merged PRs (30d)
28

Description

Go to [the Kubernetes group](https://groups.google.com/g/kubernetes-security-announce) to view the announcement.

Follow the on-call runbook to backport fixes to all supported versions.

Contributor guide

Open the contributing guide

Research direction

Start with the Kubernetes security announcement linked in the issue, then follow the on-call runbook to identify the required fix and all supported versions. Done means the CVE remediation is backported across those versions and the results are verified according to the runbook.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, kubernetes
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.