Database/Container, Kubernetes & orchestration
CSI Driver NFS: Path traversal via `subDir` lets a tenant delete unintended directories on the shared NFS server
CVSS 6.5CVE-2026-3864Container, Kubernetes & orchestrationcurated
Impact
Path traversal via subDir lets a tenant delete unintended directories on the shared NFS server; cross-tenant data destruction
Who can reach it
Cluster user able to create a PV/PVC with a crafted subDir
What to do
DaemonSet/controller rollout; add admission validation on subDir. High priority for neoclouds sharing one NFS backend across tenants
References
Related entries
- CSI Driver SMB: Same `subDir` path traversal against a shared SMB serverCVE-2026-3865 · CSI Driver SMBMedium
- Contour: fallback certificate with JWT providers lets SNI-less requests skip JWT verificationCVE-2026-50149 · Projectcontour Contour ingress controller (HTTPProxy fallback certificate + jwtProviders)Medium
- Envoy Gateway: unbounded gzip decompression of a tenant-supplied Wasm URL OOM-kills the shared controllerCVE-2026-53716 · Envoy Gateway control plane (Wasm HTTP fetcher, getFileFromGZ)Medium
- Envoy Gateway: tar header size is trusted before validation, so one OCI Wasm layer crash-loops the controllerCVE-2026-53717 · Envoy Gateway control plane (OCI Wasm image fetcher, extractWasmPluginBinary)Medium
- Envoy Gateway: a SecurityPolicy on a TCPRoute without spec.authorization panics translation and stalls xDSCVE-2026-53719 · Envoy Gateway control plane (translateSecurityPolicyForRoute, SecurityPolicy on TCPRoute)Medium
- doco-cd: artifact-supplied config can turn off its own signature verification, bypassing OCI trust policyCVE-2026-54248 · doco-cd (GitOps controller, OCI artifact signature verification)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.