CVE-2026-29064

Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:zarf:*:*:*:*:*:*:*:*

History

11 Mar 2026, 00:28

Type Values Removed Values Added
CPE cpe:2.3:a:lfprojects:zarf:*:*:*:*:*:*:*:*
References () https://github.com/zarf-dev/zarf/releases/tag/v0.73.1 - () https://github.com/zarf-dev/zarf/releases/tag/v0.73.1 - Product, Release Notes
References () https://github.com/zarf-dev/zarf/security/advisories/GHSA-hcm4-6hpj-vghm - () https://github.com/zarf-dev/zarf/security/advisories/GHSA-hcm4-6hpj-vghm - Exploit, Vendor Advisory
First Time Lfprojects
Lfprojects zarf
Summary
  • (es) Zarf es un gestor de paquetes nativo Airgap para Kubernetes. Desde la versión 0.54.0 hasta antes de la versión 0.73.1, una vulnerabilidad de salto de ruta en la extracción de archivos permite que un paquete Zarf específicamente diseñado cree enlaces simbólicos apuntando fuera del directorio de destino, lo que permite la lectura o escritura arbitraria de archivos en el sistema que procesa el paquete. Este problema ha sido parcheado en la versión 0.73.1.

06 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 17:16

Updated : 2026-03-11 00:28


NVD link : CVE-2026-29064

Mitre link : CVE-2026-29064

CVE.ORG link : CVE-2026-29064


JSON object : View

Products Affected

lfprojects

  • zarf
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')