Posted by Vyom Yadav on Sep 28 Hello Kubernetes Community, A security issue was discovered in Kubernetes where a malicious tar binary in a container may be able to write files to arbitrary paths on the local machine of a user running kubectl cp on Windows, limited only by the permissions of the local user. This issue has been rated *Medium* (CVSS calculator: https://www.first.org/cvss/calculator/3.1) (score 6.5), and assigned *CVE-2026-19444*. *Am I vulnerable?* You are...

Read the full article at oss-security →