CLEANSTART-2026-OB24504
Dashboard / Vulnerabilities / CLEANSTART-2026-OB24504
CLEANSTART-2026-OB24504
Summary: Previously, resolving relative paths containing parent directory ('
Details: Multiple security vulnerabilities affect the kube-state-metrics package. Previously, resolving relative paths containing parent directory ('. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-OB24504.json, https://osv.dev/vulnerability/CVE-2026-33818, https://osv.dev/vulnerability/CVE-2026-39821, https://osv.dev/vulnerability/CVE-2026-39822, https://osv.dev/vulnerability/CVE-2026-41178, https://osv.dev/vulnerability/CVE-2026-42504, https://osv.dev/vulnerability/CVE-2026-42505, https://osv.dev/vulnerability/CVE-2026-46600, https://osv.dev/vulnerability/CVE-2026-56852, https://osv.dev/vulnerability/CVE-2026-56858, https://osv.dev/vulnerability/CVE-2026-56860, https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g, https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf, https://nvd.nist.gov/vuln/detail/CVE-2026-33818, https://nvd.nist.gov/vuln/detail/CVE-2026-39821, https://nvd.nist.gov/vuln/detail/CVE-2026-39822, https://nvd.nist.gov/vuln/detail/CVE-2026-41178, https://nvd.nist.gov/vuln/detail/CVE-2026-42504, https://nvd.nist.gov/vuln/detail/CVE-2026-42505, https://nvd.nist.gov/vuln/detail/CVE-2026-46600, https://nvd.nist.gov/vuln/detail/CVE-2026-56852, https://nvd.nist.gov/vuln/detail/CVE-2026-56858, https://nvd.nist.gov/vuln/detail/CVE-2026-56860
Affected packages
Package
Name: kube-state-metrics
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
