VYPR
Moderate severityNVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

CVE-2026-54250

Description

K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names can be written to arbitrary locations on the filesystem when an administrator restores the archive as a compressed etcd snapshot. This vulnerability is fixed in 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/k3s-io/k3sGo
>= 1.35.0-rc1, < 1.35.31.35.3
github.com/k3s-io/k3sGo
>= 1.34.0-rc1, < 1.34.61.34.6
github.com/k3s-io/k3sGo
< 1.33.101.33.10

Affected products

4

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.