Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfprojects
Lfprojects zarf |
|
| CPEs | cpe:2.3:a:lfprojects:zarf:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfprojects
Lfprojects zarf |
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zarf-dev
Zarf-dev zarf |
|
| Vendors & Products |
Zarf-dev
Zarf-dev zarf |
Fri, 06 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1. | |
| Title | Zarf: Symlink targets in archives are not validated against destination directory | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-06T16:13:17.614Z
Updated: 2026-03-06T19:33:38.362Z
Reserved: 2026-03-03T20:51:43.482Z
Link: CVE-2026-29064
Updated: 2026-03-06T19:31:14.526Z
Status : Analyzed
Published: 2026-03-06T17:16:34.003
Modified: 2026-03-11T00:28:49.547
Link: CVE-2026-29064
No data.
ReportizFlow