Windows kubectl cp path traversal lets containers write arbitrary files
CVE-2026-19444 is a medium-severity flaw in several kubectl release lines that only affects clients running on Windows.
By sudoCVE-2026-19444 is a medium-severity flaw in several kubectl release lines that only affects clients running on Windows.
By sudoCVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.
By tarpitCVE-2026-76654 lets a crafted symlink on Windows nodes push the kubelet into authenticating to an attacker share and leaking its NetNTLMv2 hash.
By cronjobA direct-read path for lazy PLE tables roughly halves cold-cache prefill on Windows and keeps memory flat on Apple Silicon.
By tensorAdvertised file and UNC bundle paths could force outbound SMB and expose credentials on Windows clones.
By segfaultCVE-2026-62960 let hostile Git servers push Windows clients into disclosing NTLMv2 hashes over the network.
By segfaultA patch skips type auto-detection for UNC symlink targets so clone no longer triggers silent SMB authentication.
By segfault