What is CVE-2026-15687?
A security issue (CVE-2026-15687) in the Kubernetes Java client library allows a compromised pod to create files in arbitrary locations on the client machine during copy operations via `copyDirectoryFromPod` when `enableTarCompressing` is false. Users are advised to update the library or enable tar compression.
Azərbaycanca: Kubernetes Java client kitabxanasında aşkar edilmiş CVE-2026-15687 boşluğu, təhlükəyə məruz qalmış pod-un 'copyDirectoryFromPod' əməliyyatı zamanı müştəri maşınında ixtiyari fayllar yaratmasına imkan verir. Bu zəiflik yalnız 'enableTarCompressing' false olduqda baş verir, ona görə də istifadəçilər kitabxananı yeniləməli və ya tar sıxışdırmasını aktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Under what condition can CVE-2026-15687 be exploited in the Kubernetes Java client library?
This vulnerability can only be exploited during the `copyDirectoryFromPod` operation when the `enableTarCompressing` parameter is set to false.
What measures are recommended to protect against CVE-2026-15687?
Users are advised to update the library or enable tar compression.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.