VYPR

Velero

by Velero

Source repositories

CVEs (2)

  • CVE-2026-32637MedAug 25, 2026
    risk 0.31cvss —epss 0.01

    Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that…

  • CVE-2020-3996MedOct 22, 2020
    risk 0.29cvss 5.5epss 0.00

    Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorized users.