CVE-2026-29064

Source
https://cve.org/CVERecord?id=CVE-2026-29064
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29064.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-29064
Aliases
Downstream
Related
Published
2026-03-06T16:13:17.614Z
Modified
2026-04-10T05:42:29.012110Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Zarf: Symlink targets in archives are not validated against destination directory
Details

Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29064.json",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/zarf-dev/zarf

Affected ranges

Type
GIT
Repo
https://github.com/zarf-dev/zarf
Events

Affected versions

Other
nightly
v0.*
v0.54.0
v0.55.0
v0.55.1
v0.55.2
v0.55.3
v0.55.4
v0.55.5
v0.55.6
v0.56.0
v0.57.0
v0.58.0
v0.58.0-rc1
v0.59.0
v0.60.0
v0.60.0-rc1
v0.61.0
v0.61.0-rc1
v0.61.1
v0.61.2
v0.62.0
v0.63.0
v0.63.0-rc1
v0.64.0
v0.65.0
v0.65.0-rc1
v0.65.1
v0.66.0
v0.67.0
v0.67.0-rc1
v0.68.0
v0.68.1
v0.69.0
v0.69.0-rc1
v0.70.0
v0.70.1
v0.71.0
v0.71.1
v0.72.0
v0.72.0-rc1
v0.73.0
v0.73.1-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29064.json"