Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN946 _____________________________________________________________________ DATE : 29/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running kubectl versions prior to 1.34.12, 1.35.8, 1.36.5. ===================================================================== https://groups.google.com/g/kubernetes-announce/c/kPN22R7cjZo _____________________________________________________________________ [Security Advisory] CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes Vyom Yadav 28 sept. 2026, 13:26:29 Hello Kubernetes Community, A security issue was discovered in Kubernetes where a malicious tar binary in a container may be able to write files to arbitrary paths on the local machine of a user running kubectl cp on Windows, limited only by the permissions of the local user. This issue has been rated Medium (CVSS calculator: https://www.first.org/cvss/calculator/3.1) (score 6.5), and assigned CVE-2026-19444. Am I vulnerable? You are affected if you run the kubectl client on Windows and use kubectl cp to copy files from a container whose contents you do not fully control. This issue only affects clients on Windows platforms; Linux and macOS clients are not affected. To determine whether your kubectl client is an affected version, run: kubectl version --client Affected Versions kubectl v1.34.0 to v1.34.11 kubectl v1.35.0 to v1.35.8 kubectl v1.36.0 to v1.36.4 How do I mitigate this vulnerability? Prior to upgrading, this vulnerability can be mitigated by only copying files from containers you trust, or by avoiding kubectl cp from untrusted containers on Windows. Fixed Versions kubectl >= v1.34.12 kubectl >= v1.35.9 kubectl >= v1.36.5 If you find evidence that this vulnerability has been exploited, please contact secu...@kubernetes.io Additional Details See the GitHub issue for more details: https://github.com/kubernetes/kubernetes/issues/141294 Acknowledgements This vulnerability was reported by Moriel Harush. The issue was fixed and coordinated by Marly Salazar, Maciej Szulik, and Vyom Yadav. Thank You, Vyom Yadav on behalf of the Kubernetes Security Response Committee ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================