GHSA-jxr7-mqhw-9p98

Suggest an improvement
Source
https://github.com/advisories/GHSA-jxr7-mqhw-9p98
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jxr7-mqhw-9p98/GHSA-jxr7-mqhw-9p98.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jxr7-mqhw-9p98
Aliases
Downstream
CGA (20)
MINI (2)
Published
2026-07-14T17:54:14Z
Modified
2026-09-10T03:50:52Z
Severity
  • 5.8 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H CVSS Calculator
Summary
K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
Details

Summary

A path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names (e.g., ../../../../etc/password) can be written to arbitrary locations on the filesystem when an administrator restores the archive as a compressed etcd snapshot.

Mitigations

  • Enable golang's built-in insecure path protections when restoring snapshots by setting theGODEBUG environment variable:
    GODEBUG=zipinsecurepath=0 k3s server --cluster-reset --cluster-reset-restore-path=/path/to/snapshot.zip
    
  • Manually extract the snapshot from the zip archive before restoring it. If the snapshot to be restored does not end with .zip, the vulnerable extraction code will not be executed.

Additional Notes

Administrators should be aware of the cautions noted in the "Security" section of the documentation on Restoring Snapshots.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-14T17:54:14Z",
    "nvd_published_at":  "2026-06-25T19:16:41Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/k3s-io/k3s

Package

Name
github.com/k3s-io/k3s
View open source insights on deps.dev
Purl
pkg:golang/github.com/k3s-io/k3s

Affected ranges

Type
SEMVER
Events
Introduced
1.35.0-rc1
Fixed
1.35.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jxr7-mqhw-9p98/GHSA-jxr7-mqhw-9p98.json"

Go / github.com/k3s-io/k3s

Package

Name
github.com/k3s-io/k3s
View open source insights on deps.dev
Purl
pkg:golang/github.com/k3s-io/k3s

Affected ranges

Type
SEMVER
Events
Introduced
1.34.0-rc1
Fixed
1.34.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jxr7-mqhw-9p98/GHSA-jxr7-mqhw-9p98.json"

Go / github.com/k3s-io/k3s

Package

Name
github.com/k3s-io/k3s
View open source insights on deps.dev
Purl
pkg:golang/github.com/k3s-io/k3s

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.33.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jxr7-mqhw-9p98/GHSA-jxr7-mqhw-9p98.json"